Researchers report that a previously undocumented Brazilian banking malware operation delivers a toolkit called “KREMLIN” that targets Google Chrome and Microsoft Edge. The malware hijacks browser activity to steal user credentials and session tokens, using a malicious browser extension as part of its infection chain.
Elastic Security Labs tracks the activity under the moniker REF9334 and says it has been active since at least May 2025. Reports indicate the operator uses lures that impersonate multiple Brazilian banks to entice users into installing or running the malware components. Both outlets frame the activity as a credential and session-theft campaign focused on browser sessions.
While one outlet notes the campaign is not related to Russia despite the “KREMLIN” name, the other emphasizes the malware’s banking-oriented operation and the use of Chrome and Edge extensions. The shared focus across sources is the same threat behavior: compromising browser sessions to capture sensitive account data and maintain access through stolen tokens.