Skip to content
KREMLIN Banking Malware Targets Brazilian Users via Malicious Browser Extensions

KREMLIN Banking Malware Targets Brazilian Users via Malicious Browser Extensions

First seen 15 Sep 2026, 19:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 21:07 UTC
  • KREMLIN malware targets Brazilian banking users through malicious browser extensions.
  • The operation has been active since May 2025, with over 1,500 infections reported.
  • Attackers utilize Ethereum smart contracts to dynamically update their command-and-control infrastructure.

Elastic Security Labs has identified a Brazilian banking malware operation named KREMLIN, active since May 2025, targeting users through malicious browser extensions on Chrome and Edge. The malware employs multi-stage JavaScript loaders and custom C++ installers to steal credentials and session tokens. Attackers use lures impersonating twelve Brazilian banks and leverage Ethereum smart contracts to conceal their infrastructure and dynamically update command-and-control endpoints. The KREMLIN operation has been tracked through seven campaigns over 15 months, disrupting over 1,500 infections so far. The malware's infection chain begins with a JavaScript file disguised as a banking document, leading to the installation of a malicious browser extension. This extension bypasses Chromium's integrity mechanisms, posing a significant threat to Brazilian financial institutions and users. Current efforts are underway to mitigate the impact of this malware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-05-01
KREMLIN operation identified
Elastic Security Labs began tracking the REF9334 malware operation targeting Brazilian banks.
Elastic Security Labs
2026-09-15
Malicious browser extension discovered
KREMLIN malware installs itself via a browser extension that bypasses security mechanisms.
The Hacker News
2026-09-15
Over 1,500 infections disrupted
Threat Command registered a kill switch domain to temporarily disrupt KREMLIN infections.
Elastic Security Labs

More articles in this cluster (2)

Following this threat?

Track APT31, GemStone and Kremlin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed