# REF9334

> As of 2026-09-16, REF9334 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 32 techniques across 9 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1176 (Software Extensions), T1539 (Steal Web Session Cookie).

- **Tracked threats:** 2
- **Categories:** MALWARE
- **As of:** 2026-09-16

## ATT&CK techniques observed

32 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (8), Command and Control (5), Credential Access (5), Execution (4), Discovery (3), Persistence (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1176](https://intel.threadlinqs.com/technique/T1176) Software Extensions — Persistence — observed in 2 of 2 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 1 of 2 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 1 of 2 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Credential Access — observed in 1 of 2 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Credential Access — observed in 1 of 2 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 1 of 2 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 1 of 2 tracked threats

## Tracked threats

- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension](https://intel.threadlinqs.com/threat/TL-2026-2544) — HIGH
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials](https://intel.threadlinqs.com/threat/TL-2026-2525) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/REF9334
