Cybercriminals running a Brazilian banking operation dubbed KREMLIN are hijacking Google Chrome and Microsoft Edge to steal credentials and session tokens, in a campaign tracked by Elastic Security Labs as REF9334 and active since at least May 2025.[1][14][12] Researchers say the malware ecosystem abuses Chromium-based browsers by surreptitiously installing a malicious extension that can capture banking logins and authenticated web sessions, enabling account takeover and large-scale fraud.[1][3][4]
According to Elastic Security Labs and subsequent reporting, REF9334 relies on Portuguese-language lures that impersonate invoices, business documents and records from more than a dozen Brazilian financial institutions to trick victims into opening malicious JavaScript files.[1][3][14] Once executed, those scripts kick off a multi-stage chain that uses Node.js-based loaders and custom native installers to deploy the KREMLIN toolkit and prepare the browser environment for extension hijacking.[1][8][14] Analysts note that code references to the handle Kr3mlin4rt1st suggest a cybercriminal origin and that the malware’s name does not indicate any operational link to the Russian state.[14]
At the core of the toolkit is a Chrome and Edge extension commonly surfaced under the name AVSync System Inc., which is planted directly into the browser profile rather than installed through normal user-driven mechanisms.[2][5][9] Technical analyses show that KREMLIN manipulates Chromium’s Secure Preferences files, forges required HMAC and MAC integrity values, and enables developer mode so the browser accepts the extension as if it were legitimately installed.[2][8][15] Once active, the extension gains broad access to tabs, cookies and browser storage, allowing it to exfiltrate credentials, session tokens, page HTML, and screenshots while intercepting sensitive web requests.[2][4][8]
The operation further uses Ethereum smart contracts as a distributed notebook for command-and-control and payload locations, periodically updating contract data to rotate infrastructure and complicate takedown efforts.[1][8][15] Threat intelligence platforms reporting on REF9334 note that after seeding a canary domain to monitor traffic, investigators observed at least 1,515 infected hosts checking in, with roughly 98.75% of them located in Brazil, underscoring the campaign’s tight geographic focus.[15][14] This concentration on Brazilian banking users aligns with the language of the lures and suggests attackers are targeting domestically focused financial activity, though nothing prevents the tools from being repurposed against other regions.[14][12]
Public reporting to date describes KREMLIN’s browser takeover techniques as abusing and bypassing Chromium integrity checks rather than exploiting a single documented browser vulnerability, and no specific CVE identifiers or CVSS scores have yet been associated with the campaign.[1][8][15] That leaves defenders dependent on configuration hardening and behavioral detection: enforcing strict enterprise policies for browser extensions, monitoring for unauthorized modification of Secure Preferences files, and blocking unknown extensions that request access to cookies, tabs and developer features.[2][8] Financial institutions are also advised to watch for spikes in anomalous authenticated sessions, introduce stronger out-of-band transaction verification, and educate customers about opening unsolicited “bank” documents that arrive via email or messaging apps.[3][4][12]
Researchers warn that REF9334 remains an active threat, with its modular JavaScript loaders, native installers, and browser extension components giving operators ample room to evolve their tooling and target new financial platforms.[1][8][14] Intelligence feeds already list the campaign among trending banking-malware threats, highlighting its use of modern browser cryptography such as App-Bound OSCrypt keys to unlock stored secrets and stressing that traditional password theft detection may miss session-token hijacking.[8][15] Security teams in Brazil and beyond are urged to incorporate indicators from the KREMLIN ecosystem into monitoring, test browser-hardening baselines against simulated extension abuse, and treat suspicious browser preference changes as potential precursors to credential and session theft.[8][12]
References
- KREMLIN Banking Malware Hijacks Chrome and Edge to …
- Windows осталась без официальной заплатки на …
- Chrome and Edge browsers hijacked by KREMLIN …
- KREMLIN Banking Malware Infects Over …
- Telegram запустил ботов-секретарей, мошенники уже взяли их в …
- ZeroHour — live cybersecurity & AI intelligence dashboard
- Уязвимость в Notepad++ позволяет подменять обновления и заражать устройства
- RealGround News – Active AI Security Incident Feed
- Trending Threat Actors – Mallory.ai
- 慢霧:KREMLINマルウェアがイーサリアムスマートコントラクトを利用して攻撃インフラを動的に更新
