CiberLATAMbywhalemate

Colombian Banks Targeted by Digital Fraud Panel

Lumu found a panel impersonating 15 Colombian banks, while KREMLIN malware is also hitting browsers in Brazil.

Whalemate Labs · AI-assisted researchPublished:3 min read

Lumu identified a fraud panel that impersonates 15 Colombian financial institutions with a single codebase and requests dynamic codes, card data, and, in six cases, live facial biometrics. At the same time, technical research is tracking the Brazilian malware KREMLIN, active since at least May 2025.

Lumu has published research on ShadowParasite describing a fraud panel that impersonates 15 Colombian financial institutions using a single codebase. The scheme asks for a six-digit dynamic code and card data, and in six of those 15 entities it also captures live facial biometrics.

What does the ShadowParasite campaign show?

ShadowParasite is designed to mimic bank validation processes through an interface that can be adapted to multiple institutions. According to Lumu, the panel uses one codebase to replicate 15 Colombian financial entities, which points to an operation built to scale without rebuilding each fraud flow from scratch. Collecting a dynamic code, card details, and, in some cases, live facial biometrics broadens the theft of identity and credentials.

What do the reports say about fraud expanding across the region?

Bloomberg Línea reported that financial fraud in Latin America can move from one country to another within weeks. In that coverage, Colombia, Mexico, and Peru appear among the countries exposed to these new fraud methods, driven by the growth of digital financial services.

The Paypers, for its part, published a report on the evolution of digital payment fraud in LATAM and the emerging regulatory challenges. Taken together, those pieces suggest the region is seeing faster campaigns with more adaptation capability, and growing pressure on banks and regulators to make decisions in real time.

What other cases show the same trend?

In Brazil, Elastic Security Labs documented that the KREMLIN banking malware operation, also tracked as REF9334, has been active since at least May 2025. The toolkit combines JavaScript loaders, a C++ installer, and malicious extensions to compromise Chrome and Edge, steal credentials, cookies, and session tokens, and impersonate a dozen Brazilian banks.

Additional technical research shows that the malware directly modifies the Secure Preferences file in Chromium-based browsers, along with the associated HMAC and integrity keys. That allows it to force-install a malicious extension identified as AVSync System Inc., with a specific ID, as if the user had approved it, bypassing Chrome and Edge App-Bound Encryption and integrity controls.

Other technical sources attribute at least seven attack waves over about 15 months to the campaign, with more than 1,500 tracked infections. Those reports also say the operators use Ethereum smart contracts to update the command-and-control infrastructure and the extension configuration, which makes the operation harder to dismantle.

How are banks and regulators responding?

In Guatemala, the Superintendency of Banks examined new threats to financial supervision and devoted a conference to resilience against hybrid fraud and attacks using generative AI. In Peru, Infobae warned that information tied to an empty bank account can still be useful for preparing targeted fraud and recommended enabling multifactor authentication when available.

The regional context is also reflected in Panama, where Revista E&N reported, citing an Experian study, that 68% of Panamanians received at least one fraud attempt during the past year. Together, these cases show an ecosystem in which credentials, open sessions, and partial data remain valuable to attackers, even when an account no longer has funds.

Sources

View all