#ElasticSecurityLabs
Banking malware using KREMLIN silently force-installs Chrome and Edge extensions to steal credentials and session tokens. Elastic Security Labs linked 1,515 infections to a Brazilian threat actor. #KREMLIN #ElasticSecurityLabs #Brazil
Malware Bypasses Browser Checks To Force Install Chrome, Edge Extensions
A banking malware campaign active since mid-2025 has used the KREMLIN toolkit to silently install malicious Chrome and Edge extensions that steal credentials, session tokens, and browser data. Elastic Security Labs linked the operation to a Brazilian threat actor, confirmed 1,515 infected systems, and disrupted part of the campaign by registering a key anti-sandbox domain. #KREMLIN #ElasticSecurityLabs #REMCOS #PulsarRAT #Brazil
www.hendryadrian.com
September 17, 2026 at 12:00 AM
New TCLBanker malware targets 59 banking, fintech, and crypto platforms using trojanized MSI installer for Logitech AI Prompt Builder. Features self-spreading worm modules on WhatsApp and Outlook. #TCLBanker #FintechThreat #Logitech
New TCLBanker malware self-spreads over WhatsApp and Outlook
TCLBanker is a new banking trojan that targets 59 banking, fintech, and cryptocurrency platforms using a trojanized MSI installer for Logitech AI Prompt Builder to infect systems. It also includes self-spreading worm modules for WhatsApp and Outlook, and Elastic Security Labs says it may represent a major evolution of the Maverick/Sorvepotel family. #TCLBanker #ElasticSecurityLabs #Maverick #Sorvepotel #Logitech
www.hendryadrian.com
May 8, 2026 at 7:15 AM
Elastic scopre RoningLoader, loader multistadio di DragonBreath che abusa PPL e driver firmati per distribuire gh0st RAT modificato contro utenti Windows.

#apt #APTQ27 #cina #DragonBreath #ElasticSecurityLabs #RoningLoader
www.matricedigitale.it/2025/11/17/m...
November 17, 2025 at 12:59 PM