KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News, Tuesday, September 15th, 2026
The Hacker News reports that Elastic Security Labs uncovered KREMLIN, a Brazilian banking malware toolkit hijacking Chrome and Edge.
Elastic Security Labs disclosed a Brazilian banking malware operation it tracks as REF9334, active since May 2025 and built around a toolkit named KREMLIN. The chain combines multi-stage JavaScript loaders, custom C++ installers and malicious browser extensions, and uses Ethereum smart contracts as command-and-control resolvers so operators can rotate endpoints without losing access.
The installer defeats Chrome's Secure Preferences integrity protection via a Phantom Extension technique, side-loading an extension that lifts cookies, session tokens, localStorage and sessionStorage.
Elastic counted 1,515 infected systems, over 98 percent in Brazil, and disrupted the campaign by registering a canary domain.