KREMLIN Banking Malware
First seen Sep 16, 2026 · Updated Sep 16, 2026
A previously undocumented Brazilian banking malware toolkit dubbed KREMLIN, attributed to threat cluster REF9334, has been active since at least May 2025. The operation uses phishing lures impersonating a dozen Brazilian banks to trick victims into installing a malicious browser extension on Chrome and Edge, enabling credential and session token theft.
Technical Analysis
REF9334 distributes KREMLIN via phishing campaigns that spoof at least twelve Brazilian financial institutions, tricking victims into sideloading a malicious browser extension into Chrome and Edge. Once installed, the extension operates with elevated browser permissions to intercept banking session cookies, authentication tokens, and submitted credentials, likely enabling session hijacking and transaction manipulation without triggering MFA. The attack vector relies on social engineering rather than a specific software vulnerability, with no CVE currently associated with the campaign. Persistence is achieved through the browser extension mechanism, which can survive password changes if session tokens or refresh tokens are not fully invalidated. Because browser extensions and stored session tokens are also leveraged by AI browser-automation agents and RAG-connected assistants that authenticate to web services via the browser, a similar extension-hijacking technique could be repurposed to exfiltrate API keys, OAuth tokens, or session credentials used by such agents, extending the risk beyond consumer banking into enterprise AI tool-use contexts.
Affected Systems
Google Chrome and Microsoft Edge browsers on Windows endpoints used to access Brazilian online banking portals; potentially any system where employees install browser extensions from untrusted sources
Indicators of Compromise
- Malicious browser extension (name/ID not disclosed in source reporting)
- Phishing domains impersonating Brazilian bank brands (specific domains not disclosed)
- Associated C2 infrastructure tracked by Elastic Security Labs under REF9334 (indicators not disclosed in source)
Remediation Steps
- 1
Restrict extension installation
Enforce enterprise policy to allow only allow-listed browser extensions from verified publishers in Chrome and Edge.
- 2
Audit installed extensions
Review all browser extensions across endpoints for unauthorized or unsigned add-ons, especially those requesting broad host permissions.
- 3
Revoke and rotate sessions
Force logout and rotate session tokens/cookies for banking and other sensitive web applications following suspected compromise.
- 4
User awareness training
Educate employees and customers on phishing lures impersonating banks and the risks of installing browser extensions from unofficial sources.
- 5
Deploy endpoint monitoring
Use EDR to detect anomalous browser extension installation events and unusual outbound traffic from browser processes.
- 6
Enable MFA with phishing-resistant methods
Adopt FIDO2/WebAuthn-based authentication where possible to reduce impact of stolen credentials and session tokens.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.