Malware Bypasses Browser Checks to Force Install Chrome, Edge Extensions
Elastic said 1,515 systems were infected, with 98.75% in Brazil, as the malware used Ethereum to hide configuration updates and evade takedowns.
- Elastic Security Labs disclosed the KREMLIN banking malware campaign, dubbed REF9334, earlier this week, targeting Brazilian users through malicious Chrome and Microsoft Edge extensions that hijack browser sessions.
- Active since at least May 2025, the malware ecosystem employs multi-stage loaders and Ethereum smart contracts to manage attack infrastructure. Operators use blockchain technology to evade disruption while maintaining control over infected systems.
- Researchers traced 1,515 infections, with 98% geolocated in Brazil, while the malware deploys an extension named 'AVSync System Inc.' to deceive victims into believing they have installed legitimate antivirus software.
- Despite the name KREMLIN, Elastic found no evidence connecting the campaign to Russia. Researchers registered a network canary domain that caused the malware to assume it was in a sandbox, preventing further infection.
- Between June 2025 and August 2026, Elastic identified 82 USDT transfers associated with the wallet deploying malicious contracts. The operation remains active as attackers continuously refine command infrastructure through the blockchain.
14 Articles
14 Articles
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
KREMLIN Malware Targets Browser Sessions
A new banking malware tracked as KREMLIN is reported hijacking Chrome and Edge to steal credentials and active session tokens. The activity centers on browser compromise rather than simple password collection, giving operators access...
KREMLIN malware uses Ethereum to update attack servers
KREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil.
Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft
Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.In an in-depth report published e…
A Brazilian banking campaign employs Ethereum smart contracts to update malicious servers and distribute extensions capable of stealing credentials, cookies and session tokens.
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










