Colombian Banks Targeted by Digital Fraud Panel
Lumu found a panel impersonating 15 Colombian banks, while KREMLIN malware is also hitting browsers in Brazil.
Lumu identified a fraud panel that impersonates 15 Colombian financial institutions with a single codebase and requests dynamic codes, card data, and, in six cases, live facial biometrics. At the same time, technical research is tracking the Brazilian malware KREMLIN, active since at least May 2025.
Lumu has published research on ShadowParasite describing a fraud panel that impersonates 15 Colombian financial institutions using a single codebase. The scheme asks for a six-digit dynamic code and card data, and in six of those 15 entities it also captures live facial biometrics.
What does the ShadowParasite campaign show?
ShadowParasite is designed to mimic bank validation processes through an interface that can be adapted to multiple institutions. According to Lumu, the panel uses one codebase to replicate 15 Colombian financial entities, which points to an operation built to scale without rebuilding each fraud flow from scratch. Collecting a dynamic code, card details, and, in some cases, live facial biometrics broadens the theft of identity and credentials.
What do the reports say about fraud expanding across the region?
Bloomberg Línea reported that financial fraud in Latin America can move from one country to another within weeks. In that coverage, Colombia, Mexico, and Peru appear among the countries exposed to these new fraud methods, driven by the growth of digital financial services.
The Paypers, for its part, published a report on the evolution of digital payment fraud in LATAM and the emerging regulatory challenges. Taken together, those pieces suggest the region is seeing faster campaigns with more adaptation capability, and growing pressure on banks and regulators to make decisions in real time.
What other cases show the same trend?
In Brazil, Elastic Security Labs documented that the KREMLIN banking malware operation, also tracked as REF9334, has been active since at least May 2025. The toolkit combines JavaScript loaders, a C++ installer, and malicious extensions to compromise Chrome and Edge, steal credentials, cookies, and session tokens, and impersonate a dozen Brazilian banks.
Additional technical research shows that the malware directly modifies the Secure Preferences file in Chromium-based browsers, along with the associated HMAC and integrity keys. That allows it to force-install a malicious extension identified as AVSync System Inc., with a specific ID, as if the user had approved it, bypassing Chrome and Edge App-Bound Encryption and integrity controls.
Other technical sources attribute at least seven attack waves over about 15 months to the campaign, with more than 1,500 tracked infections. Those reports also say the operators use Ethereum smart contracts to update the command-and-control infrastructure and the extension configuration, which makes the operation harder to dismantle.
How are banks and regulators responding?
In Guatemala, the Superintendency of Banks examined new threats to financial supervision and devoted a conference to resilience against hybrid fraud and attacks using generative AI. In Peru, Infobae warned that information tied to an empty bank account can still be useful for preparing targeted fraud and recommended enabling multifactor authentication when available.
The regional context is also reflected in Panama, where Revista E&N reported, citing an Experian study, that 68% of Panamanians received at least one fraud attempt during the past year. Together, these cases show an ecosystem in which credentials, open sessions, and partial data remain valuable to attackers, even when an account no longer has funds.
Sources
- ¿Tu cuenta bancaria está vacía? Ciberdelincuentes aún pueden usarla para preparar nuevos fraudesinfobae.com· Infobae
- La Superintendencia de Bancos de Guatemala analiza nuevas amenazas para la supervisión financierainfobae.com· Infobae
- KREMLIN Banking Malware Bypasses Chrome Security to ...gbhackers.com· GBHackers
- Estudio: 7 de cada 10 panameños recibieron intentos de frauderevistaeyn.com· Revista E&N
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokensthehackernews.com· The Hacker News (síntesis de Elastic Security Labs)
- Malware bypasses browser checks to force install Chrome, Edge extensionsbleepingcomputer.com· BleepingComputer
- Unmasking ShadowParasite: The Invisible Cyber Fraud ...lumu.io· Lumu
- La ruta del fraude financiero en América Latina: de Brasil a Colombia y México en pocas semanasbloomberglinea.com· Bloomberg Línea
- When AI meets fraud: why banks need real-time decisioning and industry collaborationthepaypers.com· The Paypers
- KREMLIN malware uses Ethereum to update attack serverscryptonews.net· CryptoNews / otros medios técnicos



