The KREMLIN malware has nothing to do with Russia
- Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025
- Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data
- 1,515 infections found, 98% in Brazil
Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.
In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing malware which, in turn, deploys a malicious extension in Chrome and Edge browsers.
The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users.