๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
410 ํŒ”๋กœ์ž‰ ์ค‘    89.8K ํŒฌ
๐Ÿšจ SlowMist TI Alert: KREMLIN Malware ๐Ÿšจ Recently, a Brazilian banking malware operation, #REF9334#, active since at least May 2025, was disclosed. ๐Ÿ”ด The #KREMLIN# malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data. โš ๏ธ Its malicious extensions can be installed in #Chrome# and #Edge# without user approval by bypassing Chromium integrity mechanisms, including Secure Preferences, HMACs, and App-Bound encrypted hashes. โ›“๏ธ The operation also uses #Ethereum# smart contracts as dead-drop resolvers to dynamically update C2 endpoints and payload hosting locations, making the infrastructure harder to disrupt. โš™๏ธ After registering a network canary (kill switch) domain, analysts observed 1,515 infected hosts checking in, with 98.75% located in Brazil. ๐Ÿ›ก๏ธ Security teams should monitor for related malware, browser-extension activity, and infrastructure associated with the campaign. ๐Ÿ”‘ Admin: - 0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6 ๐Ÿ“œ Smart Contracts: - 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 - 0x64Def0A6099c4DE9C413B108EAae85A3C7457615 - 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b (currently active) ๐Ÿ”Ž IOCs: ๐Ÿ“Œ Source:
๋” ๋ณด๊ธฐ