Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours.
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
About this summary. This is a short, independently written summary of an article first published by Elastic Security Labs. Cyber Security News did not report or verify the underlying story. Read the original: https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware

Source attribution: headline and facts are from Elastic Security Labs (elastic.co). Summary method: excerpt of the source description. See our source attribution policy.




