Story thread · 3 reports / 3 sources

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

thehackernews.com · 19h · first report

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

The coverage

  1. KREMLIN malware uses Ethereum to update attack servers

    crypto.news · 1h

  2. Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft

    techradar.com · 3h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.