KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Researchers uncovered KREMLIN, a previously undocumented Brazilian banking malware operation tracked as REF9334 that uses fake bank lures, malicious browser extensions, and multi-stage loaders to steal credentials and session data. The campaign hides its infrastructure with Ethereum smart contracts, and Elastic observed 1,515 infected systems checking into a network canary domain, with more than 98% located in Brazil. #KREMLIN #REF9334 #Ethereum #Elastic #Brazil

Keypoints

  • KREMLIN is a Brazilian banking malware toolkit active since at least May 2025.
  • The operation uses fake bank, invoice, and company document lures to start infection.
  • Malicious browser extensions are installed on Chrome and Edge to steal browser data.
  • Ethereum smart contracts are used to hide C2 and payload infrastructure.
  • Elastic found 1,515 infected systems, mostly in Brazil, checking the network canary domain.

Read More: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html