CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

September 15, 2026

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens Ravie LakshmananSep 15, 2026Cybercrime / Browser Security Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," security researchers Cyril François and Andrew Pease said in a technical report shared with The Hacker News.…