Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft
Date:
Wed, 16 Sep 2026 10:05:00 +0000
Description:
The KREMLIN malware has nothing to do with Russia - it is a Brazilian campaign.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025 Malware Kremlin deploys fake docs and malicious Chrome/Edge extensions to steal banking data 1,515 infections found, 98% in Brazil Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware
campaign that uses browser extensions to compromise users and steal sensitive information.
In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the
campaign uses fake banking, invoice, and business documents, to trick victims into installing malware which, in turn, deploys a malicious extension in Chrome and Edge browsers . The researchers named the malware Kremlin, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users. Latest Videos From TechRadar Watch full video here: A thousand victims The malware really makes an effort to hide and persist in
the target environment. For example, it first checks to see if its in a sandbox and if so - it simply wont run. If instead it determines that its running on a real users computer, it will deploy an extension with the name AVSync System Inc. in an attempt to trick the victim into thinking they have an antivirus addon running in the browser.
It also doesnt use a fixed C2 server, but rather stores the information on
the Ethereum blockchain, since its a lot harder to disrupt the communication between the operators and the infected machines that way. You may like Edge users beware this malicious extension can break out of the sandbox and install ransomware Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
During their investigation, Elastic researchers were able to take control of
a domain that the malware used and discovered that it had infected 1,515 systems. Almost all of them (98%) were located in Brazil. They were also able to register the network canary domain and point it to their webhost, which resulted in the loader assuming it was in a sandbox. This also meant the infections have not moved past the initial access, Elastic explained.
The full list of indicators of compromise can be found on this link . Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Via The Hacker News The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/chrome-and-edge-browsers-hijacked-by-kr emlin-malware-for-credential-and-token-session-theft
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)