KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft

Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Table of Contents
    Add a header to begin generating the table of contents

    Elastic Security Labs disclosed a previously undocumented Brazilian banking malware toolkit on September 16 that installs malicious browser extensions on Google Chrome and Microsoft Edge to steal banking credentials and session tokens. KREMLIN, active since May 2025 and attributed to threat actor REF9334, bypasses browser security checks to force-install malicious extensions that hijack active banking sessions.

    REF9334 Bypasses Chrome and Edge Extension Verification to Force Malicious Installations

    The KREMLIN toolkit modifies browser internals to bypass extension verification and installation prompts that normally protect users from unauthorized add-ons. Once KREMLIN malware executes on a victim system, it installs malicious extensions on Chrome and Edge without triggering the security warnings users would typically see when adding new browser extensions. This allows the malware to operate with the full privileges of a browser extension while evading the user awareness that would normally accompany extension installation.

    The malicious extensions hijack browser sessions to steal banking credentials, session tokens, and sensitive data during active banking transactions. By operating as installed extensions rather than external processes, KREMLIN gains access to all data passing through the browser — including form inputs, authentication cookies, and HTTPS-encrypted traffic visible to the browser before encryption or after decryption.

    Elastic Security Labs identified lures impersonating a dozen Brazilian banks to distribute the KREMLIN malware. Victims receive fraudulent communications appearing to come from their bank, directing them to download software that supposedly enhances security or provides required updates. Once installed, the malware immediately compromises the browser environment and begins credential harvesting.

    Session Token Theft Bypasses Two-Factor Authentication Protections

    Banking customers using Chrome or Edge browsers face credential theft and account takeover risk from KREMLIN infections. The malware’s ability to steal session tokens is particularly dangerous — session tokens enable attackers to hijack active banking sessions without needing passwords or satisfying two-factor authentication challenges. Once an attacker possesses a valid session token, they can access the victim’s account as if they had logged in legitimately, bypassing authentication controls entirely.

    This technique represents a significant escalation in banking trojan capabilities. Traditional banking malware focused on capturing usernames and passwords, which could be defended against with strong two-factor authentication. KREMLIN’s session hijacking approach renders those protections ineffective, since the attacker uses a token proving the user already authenticated rather than attempting to authenticate separately.

    Extension Auditing and Enhanced Browser Security Protections Recommended

    Security researchers recommend users verify installed browser extensions regularly by navigating to chrome://extensions or edge://extensions and reviewing the complete list of installed add-ons. Users should remove any unfamiliar or suspicious extensions immediately, enable Chrome’s Enhanced Safe Browsing or Edge’s SmartScreen protections, avoid downloading software from sources claiming to be bank applications unless verified through official bank channels, and monitor bank account activity for unauthorized transactions that may indicate credential compromise.

    The campaign’s current focus on Brazilian banks indicates targeted financial fraud operations, though the techniques KREMLIN demonstrates could be adapted to target banking customers in other regions. Financial institutions should alert customers to the threat and provide guidance on identifying fraudulent bank-impersonation lures.

    Browser vendors face ongoing challenges securing the extension ecosystem. While browsers implement security controls to prevent malicious extensions from being installed without user consent, malware that already executes on the system with user-level privileges can modify browser files and configuration to bypass those controls. KREMLIN’s approach highlights the gap between browser security boundaries and OS-level compromise — once malware runs outside the browser sandbox, it can subvert the browser’s internal protections from below.

    The KREMLIN toolkit’s active operation since May 2025 indicates the threat actor REF9334 has maintained a sustained campaign for over a year before Elastic Security Labs’ disclosure. This extended operational timeline suggests successful credential theft and financial fraud operations that went undetected for months. Banking customers who used Chrome or Edge browsers during this period may have had credentials stolen without realizing their browsers were compromised, particularly if the malicious extensions used names and icons that appeared legitimate or mimicked genuine banking security tools.

    Related Posts