Threats · 3h ago
Elastic says the KREMLIN operation, tracked as REF9334, has been active since at least May 2025 and is aimed at Brazilian banking users. It delivers malicious Google Chrome and Microsoft Edge extensions that steal credentials, session tokens, cookies, and browser data.
The operation starts with lures that pose as bank, invoice, or company documents and lead into a multi-stage loader. That chain checks for sandboxes, installs persistence, and then fetches its command-and-control settings from Ethereum smart contracts, while the extension itself tampers with Chromium trust data so it looks approved inside the browser; the result is a browser-level foothold that can keep stealing live sessions after a password change.
For organizations that rely on browser sign-in, the exposure sits in the session layer, not just the password vault, so cleanup can leave stolen cookies and tokens usable until the session is revoked. The blockchain-hidden control path also makes disruption less straightforward than a normal server takedown, and Elastic says the setup can still leave defenders with an unusual canary in the network path.
2 sources covering this story
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
KREMLIN targets Brazilian bank users with malicious Chrome and Edge extensions that steal credentials, session tokens, cookies, and browser data.
Malicious browser extension: inside KREMLIN banking malware
Elastic Security Labs analyzes a malicious browser extension that forges Chromium's integrity checks and pulls its C2 from Ethereum smart contracts.
Part of the PlainSec briefing for 2026-09-15