Security researchers documented a Brazilian banking malware operation called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions to steal credentials and session tokens. By September 16, 2026, the malware was using Ethereum smart contracts for command-and-control infrastructure resistant to takedown efforts.
7 reports · 6 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Security researchers have documented a previously unreported Brazilian banking malware operation called KREMLIN that has been active since at least May 2025. Its lures impersonate about a dozen Brazilian banks and install malicious extensions on Google Chrome and Microsoft Edge [thehackernews.com#1]. Elastic Security Labs tracks the activity as REF9334. The Hacker News cited a technical report det
The KREMLIN banking malware now uses Ethereum smart contracts for takedown-resistant command-and-control, while bypassing Chrome and Edge security through compromised https:// deafnews.it/en/article/kremlin -banking-malware-bypasses-chrome-and-edge-using-ethereum-smart-contracts
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and payload locations. How the attack chain works: https:// thehackernews.com/2026/09/krem lin-banking-malware-hijacks-chrome.html
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]