By Interestana AI Editorial — AI-drafted, human-overseen. How we report
KREMLIN Banking Malware Targets Chrome, Edge in Brazil

A sophisticated Brazilian banking malware operation, identified by Elastic Security Labs as REF9334 and employing a toolkit named KREMLIN, has been actively targeting users since at least May 2025. This threat actor utilizes deceptive tactics, impersonating over a dozen Brazilian financial institutions to trick victims into installing a malicious browser extension. The primary objective of the KREMLIN malware is to steal sensitive user credentials and active session tokens from popular web browsers, specifically Google Chrome and Microsoft Edge. By compromising these browsers, the attackers gain unauthorized access to users' online banking accounts and other sensitive online services, potentially leading to significant financial losses and identity theft.
The KREMLIN malware's operational methodology involves distributing its malicious payload through carefully crafted phishing campaigns. These campaigns leverage the trusted branding of well-known Brazilian banks, creating a convincing facade that encourages users to download and install what they believe to be legitimate software or updates. Once installed, the malicious browser extension operates stealthily in the background, intercepting and exfiltrating data directly from the browser. This data includes login usernames, passwords, and crucially, session tokens. Session tokens are particularly valuable to attackers as they allow for continued access to a user's account without requiring re-authentication, effectively bypassing multi-factor authentication measures in some scenarios.
Elastic Security Labs' analysis indicates that the threat actor behind REF9334 is highly organized and has demonstrated a persistent effort to refine its techniques. The malware's ability to target both Chrome and Edge, two of the most widely used browsers globally, amplifies its potential reach and impact. The impersonation of multiple banks suggests a broad targeting strategy, aiming to maximize the number of potential victims across the Brazilian financial landscape. The ongoing nature of this operation, active for over a year, underscores the evolving threat posed by banking Trojans and the constant need for enhanced cybersecurity measures by both financial institutions and their customers.
While the specific technical details of the KREMLIN toolkit's inner workings are still under investigation, its success hinges on social engineering and the exploitation of browser vulnerabilities or user trust. The stolen credentials and session tokens can be used for a variety of illicit activities, including unauthorized fund transfers, fraudulent transactions, and the sale of compromised account information on dark web marketplaces. The continued operation of such malware highlights the persistent challenges in combating financial cybercrime, particularly in regions with a high volume of online banking activity. Users are strongly advised to exercise extreme caution when downloading software or clicking on links, even if they appear to originate from trusted sources, and to ensure their browsers and security software are kept up to date.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.