A previously undocumented Brazilian banking malware operation called KREMLIN has emerged as a targeted threat against Chrome and Edge users since May 2025. Elastic Security Labs tracks the activity under the moniker REF9334, attributing the campaign to threat actors distributing malicious browser extensions that harvest credentials and session tokens from financial institutions.

The attack chain begins with phishing lures impersonating a dozen Brazilian banks. Victims receive emails or messages directing them to download what appears to be legitimate software. Once installed, the malware delivers a browser extension that injects itself into Google Chrome and Microsoft Edge. The extension operates silently in the background, capturing authentication credentials and session tokens as users log into their banking portals.

The toolkit name KREMLIN reflects the operation's scope and technical sophistication. Researchers from Elastic Security Labs identified the malware after analyzing infection patterns and command infrastructure. The attackers target financial accounts by harvesting session tokens, which allow them to bypass two-factor authentication in some scenarios and maintain persistent access to compromised banking sessions. This approach proves more effective than credential theft alone, as session tokens grant immediate access without requiring password entry.

The threat actors behind REF9334 employ social engineering as their primary delivery mechanism. Phishing campaigns impersonate major Brazilian financial institutions including Bradesco, Santander, and Itau. The fake download pages closely mirror legitimate bank websites, making detection difficult for untrained users. Once a victim executes the downloaded file, the malware establishes persistence through the browser extension mechanism, which survives browser restarts and updates.

Browser extensions present an attractive attack vector for credential harvesters. Extensions operate with elevated privileges inside the browser, allowing them to intercept all network traffic, inject code into web pages, and capture form submissions before encryption. This positions them between the user and the banking website, granting complete visibility into sensitive data exchanges.

The campaign specifically targets Brazil's financial sector, suggesting the operators possess geographic focus and local knowledge. Brazilian banking trojans have historically proven lucrative targets for cybercriminals, as the country hosts one of Latin America's largest financial ecosystems. Previous operations targeting Brazilian banks achieved significant theft volumes before disruption by authorities.

Elastic Security Labs recommends immediate action for organizations with Brazilian banking customers. Financial institutions should alert users about the KREMLIN campaign and educate them on phishing recognition. Users must verify download sources through official bank websites rather than clicking email links. Installing a reputable ad blocker and using browser security extensions from trusted vendors provides additional protection against malicious extension injection.

For individual users, several protective measures reduce infection risk. Keeping browsers and extensions updated patches vulnerabilities that malware exploits for installation. Disabling automatic extension installation and reviewing installed extensions regularly identifies suspicious toolbars or add-ons. Using browser profiles with minimal extensions for banking tasks provides isolation from infected profiles used for general web browsing.

The KREMLIN operation demonstrates the continued evolution of banking malware tactics. Rather than deploying traditional trojans that require system-level access, operators now leverage browser extensions as delivery vehicles. This approach reduces detection rates while maintaining access to financial sessions. Organizations handling Brazilian banking traffic should implement network monitoring for suspicious extension communications and educate users about the dangers of third-party software downloads.