Colombian Banks Targeted by Digital Fraud Panel
Lumu found a panel impersonating 15 Colombian banks, while KREMLIN malware is also hitting browsers in Brazil.
Lumu identified a fraud panel that impersonates 15 Colombian financial institutions with a single codebase and requests dynamic codes, card data, and, in six cases, live facial biometrics. At the same time, technical research is tracking the Brazilian malware KREMLIN, active since at least May 2025.
Lumu published an investigation into ShadowParasite that describes a fraud panel impersonating fifteen Colombian financial institutions with a single codebase. The scheme asks for a six-digit dynamic code and card data, and in six of those fifteen entities it also captures live facial biometrics.
What does the ShadowParasite campaign show?
ShadowParasite is designed to mimic bank verification processes through an interface that can adapt to multiple institutions. According to Lumu, the panel uses one codebase to replicate fifteen Colombian financial institutions, which suggests an operation built to scale without rebuilding each fraud site from scratch. Collecting a dynamic code, card details and, in some cases, live facial biometrics expands the reach of identity and credential theft.
What do the reports say about the regional spread of fraud?
Bloomberg Línea reported that financial fraud in Latin America can move from one country to another in a matter of weeks. In that coverage, Colombia, Mexico and Peru appear among the countries exposed to these new fraud tactics, driven by the growth of digital financial services.
The Paypers, meanwhile, published a report on the evolution of digital payment fraud in LATAM and the emerging regulatory challenges. The takeaway from those pieces is that the region is seeing faster campaigns, greater adaptability and growing pressure on banks and regulators to make decisions in real time.
What other cases point to the same trend?
In Brazil, Elastic Security Labs documented that the KREMLIN banking malware operation, also tracked as REF9334, has been active since at least May 2025. The toolkit combines JavaScript loaders, a C++ installer and malicious extensions to compromise Chrome and Edge, steal credentials, cookies and session tokens, and impersonate a dozen Brazilian banks.
Additional technical research says the malware directly modifies the Secure Preferences file in Chromium-based browsers and also changes the associated HMAC and integrity keys. That lets it force the installation of a malicious extension identified as AVSync System Inc., with a specific ID, as if the user had approved it, bypassing Chrome and Edge App-Bound Encryption and integrity checks.
Other technical sources attribute at least seven attack waves over about 15 months, with more than 1,500 infections tracked. Those reports also say the operators use Ethereum smart contracts to update the command-and-control infrastructure and the extension configuration, making the operation harder to dismantle.
How are banks and regulators responding?
In Guatemala, the Superintendency of Banks analyzed new threats to financial supervision and devoted a conference to resilience against hybrid fraud and generative AI attacks. In Peru, Infobae warned that information tied to an empty bank account can still be useful for preparing targeted fraud and recommended enabling multi-factor authentication when available.
The regional picture also shows up in Panama, where Revista E&N reported, citing an Experian study, that 68% of Panamanians received at least one fraud attempt in the last year. These cases point to an ecosystem where credentials, open sessions and partial data remain valuable to attackers, even when an account no longer has funds.
What does compromised remittance mean in this type of fraud?
When a campaign compromises credentials, verification codes or banking sessions, it can also affect remittance operations if the attacker gets hold of the access. In this article, the starting point is regional financial fraud, not a specific remittance case, but the risk is the same: data theft used to take over accounts or divert transactions.
Lumu described a panel that imitates Colombian banks and asks for dynamic codes, card data and, in some cases, facial biometrics. In Brazil, the KREMLIN operation steals credentials, cookies and session tokens, and modifies browsers to maintain access. Those are the kinds of techniques that can compromise transfers and financial services where remittances depend on valid authentication and session data.
Sources
- ¿Tu cuenta bancaria está vacía? Ciberdelincuentes aún pueden usarla para preparar nuevos fraudesinfobae.com· Infobae
- La Superintendencia de Bancos de Guatemala analiza nuevas amenazas para la supervisión financierainfobae.com· Infobae
- KREMLIN Banking Malware Bypasses Chrome Security to ...gbhackers.com· GBHackers
- Estudio: 7 de cada 10 panameños recibieron intentos de frauderevistaeyn.com· Revista E&N
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokensthehackernews.com· The Hacker News (síntesis de Elastic Security Labs)
- Malware bypasses browser checks to force install Chrome, Edge extensionsbleepingcomputer.com· BleepingComputer
- Unmasking ShadowParasite: The Invisible Cyber Fraud ...lumu.io· Lumu
- La ruta del fraude financiero en América Latina: de Brasil a Colombia y México en pocas semanasbloomberglinea.com· Bloomberg Línea
- When AI meets fraud: why banks need real-time decisioning and industry collaborationthepaypers.com· The Paypers
- KREMLIN malware uses Ethereum to update attack serverscryptonews.net· CryptoNews / otros medios técnicos



