LIVE · cybersecurity feed
Live wire
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

zeroday.news ·

Cybersecurity researchers have reported on a new banking malware operation, dubbed KREMLIN, which targets users of Google Chrome and Microsoft Edge browsers to steal credentials and session tokens. The operation, tracked by Elastic Security Labs as REF9334, has been active since at least May 2025 and primarily targets Brazilian banking customers through sophisticated social engineering lures.

The KREMLIN toolkit operates by installing a malicious browser extension on the victim's Chrome or Edge browser. This extension is the core mechanism for hijacking browser functionality. Once installed, it can intercept sensitive data such as login credentials entered into banking websites and active session tokens, which could allow attackers to bypass multi-factor authentication and gain unauthorized access to accounts.

The initial infection vector typically involves social engineering tactics. The threat actor impersonates a dozen prominent Brazilian banks, likely through phishing emails, malicious advertisements, or compromised websites, to trick users into downloading and installing the malicious extension. This class of attack often leverages urgency or security alerts to persuade users to take immediate action, leading to the compromise.

Browser extensions, while offering legitimate enhancements, can also be abused if they are malicious or contain vulnerabilities. In this scenario, the KREMLIN extension appears to be purpose-built for data exfiltration, exploiting the trusted position extensions hold within the browser environment to access and manipulate web content and user input. The ability to steal session tokens is particularly concerning, as it allows attackers to maintain persistent access even if victims change their passwords.

Mitigation strategies for this type of threat typically involve a multi-layered approach. Users should exercise extreme caution with unsolicited emails or messages, especially those purporting to be from financial institutions and requesting software installations or credential verification. Verifying the authenticity of such communications directly with the bank through official channels is crucial. Organizations should implement robust email security gateways, endpoint detection and response (EDR) solutions, and user awareness training programs to identify and prevent phishing attempts.

Furthermore, users and organizations should regularly review installed browser extensions, removing any that are unfamiliar or unnecessary. Keeping browsers and operating systems updated to their latest versions helps patch known vulnerabilities that malware might exploit. Implementing strong, unique passwords and enabling multi-factor authentication (MFA) on all sensitive accounts adds an additional layer of security, though session token theft can sometimes bypass MFA if not properly configured.

This incident highlights the ongoing evolution of banking malware, with threat actors increasingly focusing on browser-based attacks that leverage extensions to bypass traditional security measures. The shift towards targeting session tokens rather than just credentials demonstrates a sophisticated understanding of modern web application security and authentication mechanisms, underscoring the need for continuous vigilance and adaptive security practices.

malwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]