Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft
The KREMLIN malware has nothing to do with Russia - it is a Brazilian campaign.
Elastic Security Labs has uncovered a new Brazilian banking malware campaign dubbed REF9334, which has been active since May 2025. The malware, known as "Kremlin," utilizes fake banking, invoice, and business documents to deceive users into installing malicious extensions in Chrome and Edge browsers. The primary objective of the campaign is to target Brazilian bank users and steal sensitive information, such as browser credentials, cookies, session data, and monitor user activity.
To evade detection, the malware checks for sandbox environments and deploys a deceptive extension named "AVSync System Inc." if it detects a real user's computer. The campaign stores data on the Ethereum blockchain, making it difficult to disrupt communication between the operators and infected machines. Elastic researchers managed to take control of a domain used by the malware and discovered that it had infected 1,515 systems, with nearly all (98%) located in Brazil. The investigation revealed that the infections had not progressed beyond the initial access stage.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.