SlowMist disclosed KREMLIN, a Brazilian banking malware operation active since May 2025, which uses multi-stage loaders and malicious browser extensions to steal credentials and data. The malware bypasses Chromium security mechanisms and leverages Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, with 1,515 infected hosts primarily in Brazil.
ClickFix attacks, which use fake CAPTCHA overlays and terminal commands on compromised websites, have become mainstream malware distribution techniques affecting both PC and Mac users. Attackers exploit user fatigue from legitimate security prompts and complex interfaces, making the malicious instructions appear routine. The technique's simplicity and effectiveness have led even Kremlin-backed groups to adopt it.
ClickFix attacks, which use fake CAPTCHA overlays on compromised websites to trick users into running malicious terminal commands, have become mainstream and are infecting both PC and Mac users at scale. The technique's effectiveness stems from widespread internet fatigue, as casual users have grown desensitized to complex instructions and suspicious-seeming security prompts. Even Kremlin-backed hacking groups have adopted the method.
The Human Rights Foundation condemns WP Engine for geo-blocking access to its Tyranny Tracker website from Russia after Roskomnadzor, Russia's censorship agency, demanded it. WP Engine complied without a court order despite its 2022 statement opposing Russian censorship, effectively becoming a tool of Kremlin repression against a site documenting authoritarianism.