
highMalware
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Researchers at Elastic Security Labs have identified a previously undocumented Brazilian banking malware operation, tracked as REF9334, that delivers a toolkit called KREMLIN. Active since at least May 2025, the threat actor uses lures impersonating a dozen Brazilian banks to install malicious browser extensions on Google Chrome and Microsoft Edge, enabling credential theft and session token hijacking.
The Hacker News2 min read