KREMLIN Toolkit Targets Brazilian Bank Customers via Malicious Chrome/Edge Extensions
What Happened
Elastic Security Labs has disclosed a previously undocumented Brazilian banking malware operation it tracks as REF9334, which deploys a toolkit dubbed KREMLIN. According to Elastic, the activity has been active since at least May 2025 and uses lures impersonating a dozen Brazilian banks to trick victims into installing a malicious browser extension for Google Chrome and Microsoft Edge. The extension is reportedly used to steal credentials and session tokens.
Why It Matters
Malicious browser extensions are an effective way to bypass many endpoint and network controls, since they operate inside a trusted, already-authenticated browser session. By hijacking sessions and credentials directly at the browser layer, this toolkit could allow attackers to sidestep MFA prompts tied to login events and gain persistent access to online banking sessions. Organizations and individuals in Brazil's banking sector — and potentially any environment where employees access personal or corporate banking through unmanaged extensions — are at risk.
What Defenders Should Watch For
- Audit installed browser extensions across Chrome and Edge fleets, especially ones sideloaded outside official web stores or added outside of managed policy.
- Monitor for anomalous extension installation events and unexpected changes to browser extension permissions (e.g., broad host permissions, cookie/session access).
- Hunt for unusual outbound traffic originating from browser processes to unfamiliar domains following extension installation.
- Review phishing/lure detection controls for banking-themed impersonation content targeting employees or customers.
- Consider enforcing extension allowlisting via browser management policies (e.g., Chrome/Edge enterprise policies) to block unauthorized extension installs.
Developing Intel
This is a net-new campaign disclosure without an associated CVE, and details are still emerging from Elastic Security Labs' research. Defenders should treat the specifics above as preliminary and monitor for further technical indicators. Read the original report at The Hacker News.