KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Executive Summary
Brazilian banking malware KREMLIN, active since May 2025, uses phishing lures that impersonate dozens of banks to deliver a malicious browser extension for Chrome and Edge. The extension harvests credentials and session tokens, enabling attackers to compromise accounts. Elastic Security Labs tracks the operation under the moniker REF9334.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-15T18:54:14+00:00 - Category: threat-intel
Original Description: Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
"Life is not measured by the breaths you take, but by its breathtaking moments."
— Michael Vance