Threat Intelligence

New KREMLIN Malware Hijacks Chrome and Edge to Steal Banking Logins

The Hacker News · 16 Sept 2026
Key Takeaway Train staff to avoid opening unexpected invoice or document files from unknown senders, and regularly review installed browser extensions for anything unfamiliar or unauthorised.

Security researchers at Elastic Security Labs have uncovered a previously undocumented malware operation named KREMLIN, active since at least May 2025 and linked to a threat group tracked as REF9334. The campaign impersonates around a dozen Brazilian banks and other trusted documents, tricking victims into opening malicious JavaScript files disguised as invoices or company paperwork.

Once opened, the file triggers a multi-stage infection process that checks whether it is running on a real computer rather than a security researcher's test environment before continuing. It then installs a malicious browser extension on Chrome or Edge that can bypass built-in browser security checks, allowing attackers to steal saved credentials, session tokens, and other sensitive data. The malware also abuses a legitimate security software file to sneak its own malicious code onto the system, making it harder to detect.

Notably, the attackers use Ethereum blockchain smart contracts to store and update the addresses of their command-and-control servers, making the infrastructure more resilient and difficult for defenders to take down. While this campaign currently targets Brazilian banking customers, the techniques involved, such as browser extension abuse and blockchain-based infrastructure, could be adapted for use against other regions and industries.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.