GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

Antivirus Sep 16, 2026

GajAV - Malware Signature Update — KREMLIN / REF9334 Brazilian banking malware (malicious Chrome & Edge extension)

What this update does

We have updated the product's malware signatures to detect and block KREMLIN, a banking-fraud toolkit tracked by researchers as REF9334. 

What the threat is

KREMLIN is a credential-stealing operation that has been active since at least mid-2025 and primarily targets customers of Brazilian banks. It reaches victims through fake messages and files that impersonate around a dozen well-known banks. If a user is tricked into opening the lure, the malware quietly installs a malicious add-on (extension) into the Google Chrome or Microsoft Edge browser.

Once in place, that extension can capture banking logins, active login sessions, saved cookies, browsing activity, and other sensitive information, and send it to the attackers. Because it hijacks an already-logged-in browser session, it can be used to commit fraud even where a password alone would not be enough. Reporting indicates well over a thousand systems were affected, the overwhelming majority in Brazil.

Why it's notable

This malware is designed to be stealthy. It tampers with the browser's own internal settings so the malicious extension appears trusted and legitimate, which helps it avoid casual detection. It also tries to detect security-analysis environments and shut itself down to avoid being studied. The updated signatures target the components behind these behaviours.

What we recommend

Even with detection in place, a few practical steps meaningfully lower your risk:

  • Ensure automatic signature updates are enabled so you continue to receive protection against new variants.
  • Only install software and browser extensions from official sources, and be cautious with unexpected files or links referencing banks — especially anything urging urgent action on your account.
  • Periodically review the extensions installed in Chrome and Edge and remove any you do not recognise.
  • If you bank with, or have staff or customers connected to, Brazilian financial institutions, treat this as higher priority.
IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update - GS TROJAN: Admin Menu Editor Pro backdoor webshell access

Severity: HIGH · Priority: P2 — probable compromise, escalate on hit

This rule raises an alert when someone tries to reach the hidden backdoor file left behind by a compromised version of the Admin Menu Editor Pro plugin for WordPress. In September 2026 an attacker tampered with the official plugin update (versions 2.35 and 2.36), and sites that installed it had a concealed access file planted in them. That file lets an outsider run commands on the site. This rule watches for attempts to contact that specific file on web servers.

A hit here is a high-confidence signal, not routine noise. The file this rule looks for has no legitimate reason to exist — its presence and any attempt to reach it point to a genuine compromise. Treat an alert as a probable active intrusion: confirm whether the affected site is running one of the tampered plugin versions, and if so, escalate to incident response and check for the other signs of this backdoor (an unexpected administrator account and leftover attacker files).

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update - GS INFO: iProyal residential proxy DNS lookup

This rule raises an informational alert when a device on our network looks up the residential-proxy service iProyal. That service is named in the joint UK/US/Netherlands government advisory on an Iranian state-linked spying campaign (tracked as HEAVYGRAM / CHOSEN BRICK) as one of the outside services the attackers route their activity through to blend in with normal traffic.

Important context: iProyal is also a legitimate commercial service with entirely lawful uses, so a hit on this rule is not proof of compromise on its own. It's a low-priority lead, not an incident. The advisory itself lists this service in the "otherwise-legitimate" category, and the campaign deliberately changes its other fingerprints, which is why we watch for this softer signal.

How to treat an alert: use it as a prompt to check whether the same device shows any of the stronger warning signs from the same campaign, rather than acting on this alert alone. 

Reference: NCSC advisory on Iranian targeting of dissidents, activists and journalists (15 Sep 2026).

Sep 15, 2026

Rule note — GSGajIPS - IPS Signature Update — EXPLOIT: Kestra authentication bypass leading to unauthenticated root code execution, CVE-2026-49869

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an attacker attempts to exploit a maximum-severity flaw in Kestra, an open-source workflow-orchestration platform used to run data pipelines and automation jobs. Kestra's login check was written to leave one public configuration address open without a password, but the check was too loose: it allowed through any web address ending in the same word. An unauthenticated attacker can use that gap to reach protected functions, define their own workflow, and have Kestra run it — and because Kestra runs scripts as part of normal operation, that means running commands with the highest level of access on the server, with no credentials required. This rule watches for requests that carry the tell-tale shape of that bypass — a Kestra API address padded with extra segments so it slips past the login check while still ending in the exempted word.

A hit here is a top-urgency signal. The flaw is rated the maximum severity (10 out of 10), is confirmed under active exploitation — including to deploy cryptocurrency miners and steal cloud credentials — and government authorities have placed it on their known-exploited-vulnerabilities catalogue with an emergency patch deadline that has already passed. Because a successful attack yields full control of the server and the secrets it can reach, treat an alert as an active, serious intrusion attempt.

On a hit: identify whether the targeted system is a Kestra instance and whether it is on a fixed release (1.0.45 / 1.3.21 or later); anything earlier is vulnerable. If it is unpatched and internet-exposed, assume potential compromise and escalate to incident response immediately — review the instance for unauthorized workflow activity, look for signs of cryptomining or unexpected outbound connections, assess which cloud and database credentials the Kestra worker could reach, and rotate any that may have been exposed. Upgrading to a fixed release is the definitive fix.