# malicious approval — X 热门讨论 (2026-09-17 02:59 UTC)

## @SlowMist_Team (SlowMist) · 09-16 10:05 · ♥20 ↻1 💬2 🚨 SlowMist TI Alert: KREMLIN Malware 🚨

Recently, a Brazilian banking malware operation, #REF9334, active since at least May 2025, was disclosed.

🔴 The #KREMLIN malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data.

⚠️ Its malicious extensions can be installed in #Chrome and #Edge without user approval by bypassing Chromium integrity mechanisms, including Secure Preferences, HMACs, and App-Bound encrypted hashes.

⛓️ The operation also uses #Ethereum smart contracts as dead-drop resolvers to dynamically update C2 endpoints and payload hosting locations, making the infrastructure harder to disrupt.

⚙️ After registering a network canary (kill switch) domain, analysts observed 1,515 infected hosts checking in, with 98.75% located in Brazil.

🛡️ Security teams should monitor for related malware, browser-extension activity, and infrastructure associated with the campaign.

🔑 Admin: - 0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6 📜 Smart Contracts: - 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 - 0x64Def0A6099c4DE9C413B108EAae85A3C7457615 - 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b (currently active)

🔎 IOCs: https://t.co/mnkXUEY3py

📌 Source: https://t.co/7lTzuUNJCi https://x.com/SlowMist_Team/status/2100164210013675860