Cybersecurity researchers have uncovered a sophisticated banking malware operation in Brazil that bypasses multi-factor authentication by hijacking the browser itself, not just login credentials. The campaign installs malicious extensions to steal active session tokens, effectively walking past MFA protections.
Tracked as REF9334 by Elastic Security Labs, the threat actor has been active since at least May 2025. The attack begins with social engineering lures impersonating over a dozen Brazilian banks, tricking users into installing a malware toolkit dubbed "KREMLIN." This toolkit targets Google Chrome and Microsoft Edge browsers.
The malware's core innovation is its shift away from traditional credential capture. Instead of targeting users at the login screen, KREMLIN installs a malicious browser extension. This extension then monitors browsing activity, specifically hunting for session tokens tied to online banking platforms.
By stealing an active session token, attackers gain access to an already authenticated account. This technique renders the login-time multi-factor authentication challenge irrelevant, as the attacker isn't logging in—they are continuing an existing session.
The campaign highlights that the initial compromise relies entirely on user deception. This underscores the persistent potency of social engineering, where human psychology is exploited to bypass technical controls.
For organizations worldwide, the attack redefines the security perimeter. As critical functions increasingly operate within the browser, the extension ecosystem becomes a prime target. This incident demonstrates that browser security can no longer be an afterthought.
The research points to a dual-layer defense. For individuals, it reinforces the need for extreme caution with any extension installation prompt, even from seemingly familiar sources. For enterprises and IT administrators, it strengthens the case for enforcing strict browser extension allowlisting policies—permitting only pre-approved tools can directly block this class of threat.
This Brazilian campaign provides a clear case study in malware evolution. As authentication methods grow stronger, attackers adapt by targeting the trust placed in the browser itself, turning a common utility into a persistent backdoor.
網絡安全研究人員揭露一宗在巴西活躍的精密銀行惡意軟件行動,該行動透過劫持瀏覽器本身(而非僅登入憑證)繞過多重驗證。攻擊活動安裝惡意擴充功能以竊取有效會話令牌,從而實質避開多重驗證防護。
此威脅行為者被 Elastic Security Labs 標記為 REF9334,至少自 2025 年 5 月起活躍。攻擊始於模仿十幾間巴西銀行的社交工程陷阱,誘騙用戶安裝名為「KREMLIN」的惡意軟件工具包。該工具包針對 Google Chrome 及 Microsoft Edge 瀏覽器。
該惡意軟件的核心創新在於摒棄傳統的憑證捕獲方式。KREMLIN 並非針對登入介面的用戶,而是安裝惡意瀏覽器擴充功能。此擴充功能隨後監控瀏覽活動,專門搜尋與網上銀行平台關聯的會話令牌。
竊取有效會話令牌後,攻擊者可直接存取已驗證的帳戶。此技術使登入時的多重驗證機制失效,因為攻擊者並非重新登入——而是延續既有會話。
該攻擊活動凸顯初始入侵完全依賴用戶欺騙。這突顯社交工程的持續威脅性,即利用人類心理繞過技術控制。
對全球企業而言,此攻擊重新定義了安全邊界。隨著關鍵功能日益依賴瀏覽器運作,擴充功能生態系統已成為首要攻擊目標。此事例證明瀏覽器安全不能再被視為次要考慮。
研究指出雙重防護策略。對個人而言,此案例強化了對任何擴充功能安裝提示保持高度警惕的必要性,即使來自看似熟悉的來源。對企業及 IT 管理員而言,這進一步支持實施嚴格的瀏覽器擴充功能白名單政策——僅允許預審核工具可直接阻擋此類威脅。
此巴西攻擊活動為惡意軟件演進提供清晰案例。當驗證方法日益強固時,攻擊者透過針對瀏覽器本身所受的信任進行攻擊,將日常工具轉化為持續後門。
