KREMLIN Malware Targets Brazilian Banks via Browser Hijack
A new Brazilian banking trojan named KREMLIN hijacks Chrome and Edge to steal credentials. Researchers link the campaign to threat actor REF9334.
TL;DR
- KREMLIN is a newly documented banking malware targeting Brazilian financial institutions.
- It installs malicious extensions on Chrome and Edge to capture login data and session tokens.
- The campaign, tracked as REF9334, has been active since at least May 2025.
- Attackers use social engineering lures mimicking legitimate bank communications.
- Organizations should enforce browser extension controls and monitor for unusual session activity.
Cybersecurity researchers from Elastic Security Labs have uncovered a sophisticated Brazilian banking malware operation dubbed KREMLIN. This previously unreported threat has been actively targeting users of major Brazilian banks since at least May 2025.
The malware operates by delivering malicious browser extensions to Google Chrome and Microsoft Edge. Once installed, these extensions are used to harvest sensitive information such as login credentials and active session tokens, enabling attackers to gain unauthorized access to victim accounts.
Attack Vector and Distribution
- KREMLIN spreads through phishing emails and fake websites that mimic at least twelve Brazilian banks.
- Users are tricked into installing a malicious browser extension that appears legitimate.
- Once installed, the extension monitors browsing activity and captures form data and session cookies.
- The operation is tracked under the internal designation REF9334 by Elastic Security Labs.
Security Recommendations
- Organizations should implement strict policies on browser extension installations.
- Monitor network traffic for unauthorized data exfiltration patterns associated with known malware C2 domains.
- Educate employees about the risks of installing unknown browser add-ons.
- Use endpoint detection and response tools to identify suspicious browser behaviors.
- Regularly update and patch browsers to limit exposure to known vulnerabilities exploited in tandem with malware.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.