AI News Feed
Market watch
Cybersecurity

Elastic Security Labs Uncovers 'Kremlin' Malware Hijacking Chrome and Edge in Brazilian Banking Campaign

Elastic Security Labs says REF9334, active since May 2025, uses fake documents and malicious Chrome and Edge extensions to steal banking credentials and session data, with 1,515 infections, 98% in Brazil.

The researchers named the malware "Kremlin." They said the campaign relies on fake banking, invoice, and business documents to trick victims into installing the malware, which then deploys a malicious extension in Chrome and Edge browsers. The malware can steal browser credentials, cookies, and session information, monitor browser activity, take screenshots, and steal information from websites that victims visit. The campaign's primary goal is to target Brazilian bank users.

Elastic Security Labs found 1,515 infected systems after taking control of a domain used by the malware. Almost all of those infections, 98%, were located in Brazil. The researchers also registered a network canary domain and pointed it to their webhost, which caused the loader to assume it was in a sandbox. As a result, Elastic explained, "the infections have not moved past the initial access."

The malware attempts to hide and persist in the target environment. It first checks whether it is running in a sandbox; if it is, it will not run. If it determines it is on a real user's computer, it deploys an extension named "AVSync System Inc." to make the victim believe an antivirus addon is running in the browser.

Kremlin does not use a fixed command-and-control server. Instead, it stores information on the Ethereum blockchain, which makes it harder to disrupt communication between the operators and infected machines. Elastic Security Labs published an in-depth report earlier this week and included a link to the full list of indicators of compromise. The findings were reported by TechRadar, which cited The Hacker News.