KREMLIN Malware Targets Chrome and Edge to Steal Banking Credentials

A new banking malware named KREMLIN has been discovered, targeting Brazilian users by hijacking popular web browsers.

3 min readCybersecurity

Recent investigations have unveiled a previously unknown banking malware operation from Brazil, identified as KREMLIN. This malicious software is being monitored by Elastic Security Labs under the alias REF9334. The operation has been active since at least May 2025, employing deceptive tactics that mimic various Brazilian banking institutions. The malware is designed to install a harmful browser extension on both Google Chrome and Microsoft Edge, allowing cybercriminals to capture sensitive information such as user credentials and session tokens. The threat actor behind this operation has been successful in tricking users into downloading the extension, which then facilitates unauthorized access to their banking accounts. This highlights the growing sophistication of cyber threats targeting financial systems, emphasizing the need for users to remain vigilant and adopt robust security measures.

Cybersecurity