
KREMLIN Banking Malware Targets Brazilian Banks Through Browser Hijacking
CybersecurityMalwareBankingCredential TheftBrowser HijackingKREMLINREF9334BrazilChromeEdge
Cybersecurity researchers have discovered a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334, which has been active since at least May 2025. The threat actor uses lures impersonating a dozen Brazilian banks to install a malicious browser extension on Google Chrome and Edge browsers. The malware is designed to steal credentials and session tokens by hijacking these browsers.