www.elastic.co KREMLIN Banking Malware Targets Brazilian Users via Malicious Browser Extensions
Article Content
- •KREMLIN malware targets Brazilian banking users through malicious browser extensions.
- •The operation has been active since May 2025, with over 1,500 infections reported.
- •Attackers utilize Ethereum smart contracts to dynamically update their command-and-control infrastructure.
Elastic Security Labs has identified a Brazilian banking malware operation named KREMLIN, active since May 2025, targeting users through malicious browser extensions on Chrome and Edge. The malware employs multi-stage JavaScript loaders and custom C++ installers to steal credentials and session tokens. Attackers use lures impersonating twelve Brazilian banks and leverage Ethereum smart contracts to conceal their infrastructure and dynamically update command-and-control endpoints. The KREMLIN operation has been tracked through seven campaigns over 15 months, disrupting over 1,500 infections so far. The malware's infection chain begins with a JavaScript file disguised as a banking document, leading to the installation of a malicious browser extension. This extension bypasses Chromium's integrity mechanisms, posing a significant threat to Brazilian financial institutions and users. Current efforts are underway to mitigate the impact of this malware.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track APT31, GemStone and Kremlin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…
China-Linked Hackers Target NGOs with Chrome and Windows Exploits On September 1, 2026, Chinese threat actors UTA0560 and JungleBamboo executed phishing campaigns targeting NGOs, exploiting zero-day vulnerabilities in Google Chrome and Microsoft Windows. The attack utilized a spear-phishing email that redirected victims to a compromised U.S.-based university website, leveraging a…