security1 publisher
KREMLIN installers forge Chrome's Secure Preferences HMACs to register a stealer extension
Elastic Security Labs says the Brazilian crew it calls REF9334 has been running this since at least May 2025, writing its extension into Chromium's Secure Preferences and reading C2 addresses out of an Ethereum smart contract.
Publishers:thehackernews.com
Reality
- Evidence62
- Adoption58
- Hype gap+12
- Incentives62
- Confidence60