Brazilian banking malware KREMLIN steals credentials via browser extensions

Security researchers documented a Brazilian banking malware operation called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions to steal credentials and session tokens. By September 16, 2026, the malware was using Ethereum smart contracts for command-and-control infrastructure resistant to takedown efforts.

7 reports · 6 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Brazilian banking malware targets Chrome, Edge credentials

kite:cybersecurityother14d ago kagi ↗

Security researchers have documented a previously unreported Brazilian banking malware operation called KREMLIN that has been active since at least May 2025. Its lures impersonate about a dozen Brazilian banks and install malicious extensions on Google Chrome and Microsoft Edge [thehackernews.com#1]. Elastic Security Labs tracks the activity as REF9334. The Hacker News cited a technical report det

The KREMLIN banking malware now uses Ethereum smart contracts for takedown-resistant command-and-control, while bypassing Chrome and Edge security through compromised https:// deafnews.it/en/article/k

mastodon:infosec-exchangeother14d ago kagi ↗

The KREMLIN banking malware now uses Ethereum smart contracts for takedown-resistant command-and-control, while bypassing Chrome and Edge security through compromised https:// deafnews.it/en/article/kremlin -banking-malware-bypasses-chrome-and-edge-using-ethereum-smart-contracts

🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and

mastodon:infosec-exchangeother14d ago kagi ↗

🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and payload locations. How the attack chain works: https:// thehackernews.com/2026/09/krem lin-banking-malware-hijacks-chrome.html

🤖 KREMLIN: previously undocumented Brazilian banking malware toolkit (REF9334, active since May 2025) drops a malicious Chrome/Edge extension to steal credentials and session tokens from victims' bro

mastodon:infosec-exchangeother14d ago kagi ↗

🤖 KREMLIN: previously undocumented Brazilian banking malware toolkit (REF9334, active since May 2025) drops a malicious Chrome/Edge extension to steal credentials and session tokens from victims' browsers. 🔗 https:// thehackernews.com/2026/09/krem lin-banking-malware-hijacks-chrome.html # Malware # InfoSec # CyberSec