Malware News Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,137
6,179
2,168
Germany
The KREMLIN malware has nothing to do with Russia
  • Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025
  • Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data
  • 1,515 infections found, 98% in Brazil
Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.

In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing malware which, in turn, deploys a malicious extension in Chrome and Edge browsers.

The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users.
Full Story:
 


Hi, the important practical point is that this appears to be an installation-driven compromise, not something that hijacks Chrome or Edge merely because a victim visits an ordinary website. According to the quoted report, victims are lured with fake business or banking documents, after which malware installs a malicious browser extension. “KREMLIN” is the malware’s assigned name; the campaign described here is primarily Brazilian and the name does not establish Russian attribution.

What the reported capabilities mean​

Stealing cookies and session tokens can let an attacker reuse an authenticated session, sometimes without knowing the password or being stopped by MFA. Browser-saved credentials, screenshots and page monitoring could also expose banking details entered after infection.

The quoted figure of 1,515 infections, 98% in Brazil describes the infections reportedly observed by the researchers. It does not prove the campaign is limited to Brazil, nor that every Chrome or Edge user is exposed. Likewise, a malicious extension is part of the reported attack chain; this is not evidence of a vulnerability in the browsers themselves.

If someone installed the lure or found the extension​

Treat that as a possible device and account compromise rather than just removing an unwanted extension:

  1. Disconnect the affected computer from the network and stop using it for banking or account recovery.
  2. From a separate trusted device, change passwords for banking, email and other accounts used in that browser; revoke existing sessions and unrecognized connected access, verify recovery details and forwarding rules, and enable MFA. Change reused passwords too.
  3. Contact the bank through its official app, website or phone number and review transactions. Session theft makes waiting for an unfamiliar payment a poor strategy.
  4. Preserve the suspicious document, extension ID/name and security alerts if possible, but do not reopen the file. Those details may help diagnosis.
  5. Request individualized cleanup through MalwareTips’ Malware Removal Assistance team. Simply deleting the extension may remove one visible component without establishing that the malware which installed it is gone.

No specific indicators or validated removal procedure are included in the material supplied here, so matching only the name “KREMLIN” would be unreliable. The extension ID, file hashes, persistence details and affected-version information would need to come from Elastic’s primary technical report before being used as detection criteria.