ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Brazilian Banking Credentials and Session Tokens

highMalwareexploited in the wildimportance 70
What's new: First merged summary for this story (no prior coverage). Notable developments in the disclosure: KREMLIN's C2-resolution infrastructure shifted to Ethereum smart contracts on May 19, 2026; Elastic Security Labs reported disrupting more than 1,500 infections via a canary domain; and the group's extension-install technique was linked to APT31's GemStone campaign observed in August 2026.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Elastic Security Labs is tracking a Brazilian banking malware dubbed KREMLIN as REF9334, active since at least May 2025, which installs malicious Chrome/Edge extensions by forging Chromium integrity values and uses Ethereum smart contracts as dead-drop…

Elastic Security Labs documents KREMLIN (tracked as REF9334), a Brazilian banking malware toolkit active since at least May 2025 across seven campaigns that primarily target 12 Brazilian banks, whose brands the operation impersonates. Infection begins with a victim-run, multi-stage JavaScript loader that achieves scheduled-task persistence via a task named MicrosoftNodeRuntimeUpdater and side-loads a malicious DLL through SentinelOne's legitimate SentinelMemoryScanner.exe binary; the C++ installer aborts execution in sandboxes and VMs. The malware modifies Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install a malicious browser extension named 'AVSync System Inc.', while extracting browser encryption material including the newer App-Bound OSCrypt key. The extension harvests cookies, sessionStorage/localStorage, browsing history, screenshots, and full page HTML via a WebSocket plus CSS-disguised polling endpoints; stolen cookies and session tokens could enable account takeover even where banks use multifactor authentication. Since May 19, 2026, Ethereum smart contracts have served as dead-drop resolvers for C2 endpoints, making the infrastructure hard to disrupt, though Elastic disrupted more than 1,500 infections using a canary domain. The group also distributes Pulsar RAT and Remcos RAT, and its extension-install technique matches the 'Phantom Extension' method used by APT31's GemStone campaign in August 2026.

  • Elastic Security Labs tracks the operation as REF9334, dubbed KREMLIN: a Brazilian banking malware active since at least May 2025 across seven campaigns (both reports).
  • The malware primarily targets 12 Brazilian banks, whose brands it impersonates (GBHackers: 'primarily targeting 12 Brazilian banks'; The Hacker News: 'impersonates a dozen Brazilian banks').
  • Infection starts with a victim-run, multi-stage JavaScript loader; persistence is provided after logon by a scheduled task named MicrosoftNodeRuntimeUpdater.
  • A C++ installer DLL-sideloads the payload via SentinelOne's legitimate SentinelMemoryScanner.exe binary and aborts execution in sandboxes and VMs.
  • The malware edits Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install a malicious extension named 'AVSync System Inc.'.
  • It extracts browser encryption material, including the newer App-Bound OSCrypt key (GBHackers).
  • The extension steals cookies, sessionStorage/localStorage, browsing history, screenshots, and full page HTML via a WebSocket plus CSS-disguised polling endpoints.
  • Stolen cookies and session tokens could enable account takeover even where banks use multifactor authentication (GBHackers).

Coverage timeline

  1. · 15h ago
    The Hacker News· 65
    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    Elastic Security Labs details KREMLIN, Brazilian banking malware using malicious Chrome/Edge extensions and Ethereum smart contracts to steal credentials and session tokens.

  2. · 4h ago
    GBHackers· 70
    KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions

    Elastic Security Labs details KREMLIN, a Brazilian banking malware that implants malicious Chrome and Edge extensions by forging Chromium integrity values to steal banking sessions.