Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft
- Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025
- Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data
- 1,515 infections found, 98% in Brazil
Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.
In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing malware which, in turn, deploys a malicious extension in Chrome and Edge browsers.
The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users.
Latest Videos FromTechRadar
A thousand victims
The malware really makes an effort to hide and persist in the target environment. For example, it first checks to see if it’s in a sandbox and if so – it simply won’t run. If instead it determines that it’s running on a real user’s computer, it will deploy an extension with the name “AVSync System Inc.” in an attempt to trick the victim into thinking they have an antivirus addon running in the browser.
It also doesn’t use a fixed C2 server, but rather stores the information on the Ethereum blockchain, since it’s a lot harder to disrupt the communication between the operators and the infected machines that way.
During their investigation, Elastic researchers were able to take control of a domain that the malware used and discovered that it had infected 1,515 systems. Almost all of them (98%) were located in Brazil. They were also able to register the network canary domain and point it to their webhost, which resulted in the loader assuming it was in a sandbox. This also meant “the infections have not moved past the initial access”, Elastic explained.
The full list of indicators of compromise can be found on this link.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via The Hacker News
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025 Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data 1,515 infections found, 98% in Brazil Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser…
Recent Posts
- Outlander: Blood of my Blood season 2 has ‘great Easter eggs’ for fans four months after Outlander season 8 finished for good
- A brief history of AI executives calling for regulation
- Breville Eye Q Toaster review: A toaster with a vision
- Agentic AI is increasing the pressure on organizations to reduce cyber risk exposure
- Best Robot Vacuum of 2026: Shark, Eufy, Roborock
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023