hacker-news · Crawled Sep 15, 2026

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

8 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

KREMLIN is a Brazilian banking malware operation active since May 2025 that targets Chromium-based browsers to steal credentials, session tokens, and sensitive data. It uses multi-stage JavaScript loaders, C++ installers, and malicious browser extensions, evading sandbox detection by checking hardware properties and process names. The malware leverages Ethereum smart contracts as dead drop resolvers to dynamically update C2 infrastructure and employs DLL sideloading via a legitimate SentinelOne binary. It installs a malicious extension named 'AVSync System Inc.' that exfiltrates browser data through WebSocket and HTTP-based polling mechanisms.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 8 extracted

Type Value Detail
Domain volmira[.]site Details →
Domain zaviro[.]online Details →
Domain luizestrelhashapr[.]online Details →
Filename SentinelMemoryScanner.exe Details →
Filename SentinelAgentCore.dll Details →
MD5 ndpbidppejfanjbhfgjlohfanbfbklff Details →
GitHub Repo Phantom Extension Details →
GitHub Repo GhostChrome-X Details →

MITRE ATT&CK TTPs 37 techniques

T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1134 Access Token Manipulation · Defense Evasion T1134.001 Token Impersonation/Theft · Defense Evasion T1204 User Execution · Execution T1204.002 Malicious File · Execution T1497 Virtualization/Sandbox Evasion · Defense Evasion T1497.001 System Checks · Defense Evasion T1547 Boot or Logon Autostart Execution · Persistence T1547.001 Registry Run Keys / Startup Folder · Persistence T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087.002 Domain Account · Discovery T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control