KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Brazilian Banking Credentials and Session Tokens
Elastic Security Labs is tracking a Brazilian banking malware dubbed KREMLIN as REF9334, active since at least May 2025, which installs malicious Chrome/Edge extensions by forging Chromium integrity values and uses Ethereum smart contracts as dead-drop…
Elastic Security Labs documents KREMLIN (tracked as REF9334), a Brazilian banking malware toolkit active since at least May 2025 across seven campaigns that primarily target 12 Brazilian banks, whose brands the operation impersonates. Infection begins with a victim-run, multi-stage JavaScript loader that achieves scheduled-task persistence via a task named MicrosoftNodeRuntimeUpdater and side-loads a malicious DLL through SentinelOne's legitimate SentinelMemoryScanner.exe binary; the C++ installer aborts execution in sandboxes and VMs. The malware modifies Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install a malicious browser extension named 'AVSync System Inc.', while extracting browser encryption material including the newer App-Bound OSCrypt key. The extension harvests cookies, sessionStorage/localStorage, browsing history, screenshots, and full page HTML via a WebSocket plus CSS-disguised polling endpoints; stolen cookies and session tokens could enable account takeover even where banks use multifactor authentication. Since May 19, 2026, Ethereum smart contracts have served as dead-drop resolvers for C2 endpoints, making the infrastructure hard to disrupt, though Elastic disrupted more than 1,500 infections using a canary domain. The group also distributes Pulsar RAT and Remcos RAT, and its extension-install technique matches the 'Phantom Extension' method used by APT31's GemStone campaign in August 2026.
- Elastic Security Labs tracks the operation as REF9334, dubbed KREMLIN: a Brazilian banking malware active since at least May 2025 across seven campaigns (both reports).
- The malware primarily targets 12 Brazilian banks, whose brands it impersonates (GBHackers: 'primarily targeting 12 Brazilian banks'; The Hacker News: 'impersonates a dozen Brazilian banks').
- Infection starts with a victim-run, multi-stage JavaScript loader; persistence is provided after logon by a scheduled task named MicrosoftNodeRuntimeUpdater.
- A C++ installer DLL-sideloads the payload via SentinelOne's legitimate SentinelMemoryScanner.exe binary and aborts execution in sandboxes and VMs.
- The malware edits Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install a malicious extension named 'AVSync System Inc.'.
- It extracts browser encryption material, including the newer App-Bound OSCrypt key (GBHackers).
- The extension steals cookies, sessionStorage/localStorage, browsing history, screenshots, and full page HTML via a WebSocket plus CSS-disguised polling endpoints.
- Stolen cookies and session tokens could enable account takeover even where banks use multifactor authentication (GBHackers).
Coverage timelineoldest first · each row is one article
- · 15h agoKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News· 65
Elastic Security Labs details KREMLIN, Brazilian banking malware using malicious Chrome/Edge extensions and Ethereum smart contracts to steal credentials and session tokens.
- · 4h agoKREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
GBHackers· 70
Elastic Security Labs details KREMLIN, a Brazilian banking malware that implants malicious Chrome and Edge extensions by forging Chromium integrity values to steal banking sessions.