Threats · 3h ago

KREMLIN Puts Chrome and Edge Sessions at Risk

Elastic says the KREMLIN operation, tracked as REF9334, has been active since at least May 2025 and is aimed at Brazilian banking users. It delivers malicious Google Chrome and Microsoft Edge extensions that steal credentials, session tokens, cookies, and browser data.

The operation starts with lures that pose as bank, invoice, or company documents and lead into a multi-stage loader. That chain checks for sandboxes, installs persistence, and then fetches its command-and-control settings from Ethereum smart contracts, while the extension itself tampers with Chromium trust data so it looks approved inside the browser; the result is a browser-level foothold that can keep stealing live sessions after a password change.

For organizations that rely on browser sign-in, the exposure sits in the session layer, not just the password vault, so cleanup can leave stolen cookies and tokens usable until the session is revoked. The blockchain-hidden control path also makes disruption less straightforward than a normal server takedown, and Elastic says the setup can still leave defenders with an unusual canary in the network path.

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-15

Editions

Related stories