Back

KREMLIN Malware Bypasses Browser Protections to Target Brazilian Banks

At a glance

  • KREMLIN malware has been active since at least May 2025.
  • Malware installs Chrome and Edge extensions without user approval.
  • Approximately 1,515 systems in Brazil were identified as infected.

A malware operation tracked as REF9334 has been identified targeting Brazilian banking users by installing unauthorized browser extensions and stealing sensitive data. The campaign, using a toolkit named KREMLIN, has been active for over a year and was disrupted by security researchers.

The infection process starts when a victim opens a JavaScript file that is disguised as a legitimate bank receipt, invoice, or business document. After execution, the malware waits for the browser to close or forces it to shut down if idle, then copies a malicious extension into the user's profile directory. Developer mode is enabled, and the malware forges HMACs and encrypted hashes to make the extension appear authentic.

KREMLIN is designed to bypass Chromium-based browser integrity checks, allowing it to install extensions on Chrome and Edge without user consent. Once installed, the extension is capable of stealing cookies, session tokens, and form input data, as well as capturing screenshots, browsing history, and intercepting HTTP requests. It can also inject HTML, redirect user clicks, and receive commands through WebSocket connections.

The toolkit further exfiltrates browser databases, cookies, lists of installed extensions, and App-Bound cryptographic keys. The malware uses Ethereum smart contracts as a method to retrieve payload locations and command-and-control configurations, making its infrastructure more resilient to takedown efforts.

What the numbers show

  • REF9334 has been active since at least May 2025.
  • Elastic Security Labs identified about 1,515 infected systems.
  • The toolkit was observed in seven campaigns over 15 months.

Elastic Security Labs reported that nearly all of the 1,515 infected systems were located in Brazil. The operation is not linked to Russia, despite the toolkit's name, and specifically targets users of Brazilian banking services.

The campaign was disrupted when Elastic Security Labs registered the malware’s sandbox-canary domain. This action caused the malware loader to abort its process on infected machines, effectively halting further spread and activity of the toolkit on those systems.

The KREMLIN toolkit has been observed across seven separate campaigns within a 15-month period. Its author, using the handle Kr3mlin4rt1st, developed the toolkit to target banking users in Brazil through repeated and evolving methods.

Security researchers continue to monitor the situation and analyze the methods used by KREMLIN. The incident highlights the ongoing risks of malware targeting browser extensions and the need for continued vigilance in the banking sector.

* This article is based on publicly available information at the time of writing.