KREMLIN Banking Malware Isn't Related to Russia, But It's Stealing Chrome & Edge Credentials

The malware is just named "KREMLIN" and has no connection with Russia


A newly documented banking malware campaign is turning Google Chrome and Microsoft Edge into credential-stealing tools. Elastic Security Labs is tracking the operation as REF9334, with its KREMLIN toolkit targeting Brazilian banking users through malicious browser extensions. Just to make things clear, the name of the malware has no Russian link.

KREMLIN secretly installs a malicious browser extension

According to a report by The Hacker News, the campaign has reportedly been active since at least May 2025, using fake documents and lures impersonating around a dozen Brazilian banks. Victims are tricked into manually running a JavaScript file, which starts a multi-stage infection chain before eventually installing the malicious extension.

What makes KREMLIN particularly concerning is how it gets the extension into Chromium-based browsers. The malware modifies Chrome’s Secure Preferences file and regenerates the integrity checks used to detect unauthorized changes, allowing the extension to appear as though it was legitimately installed.

The extension reportedly masquerades as “AVSync System Inc.” and can access browser tabs, cookies and local storage. Elastic says it can capture screenshots, enumerate open tabs, extract HTML and steal session-related browser data, potentially giving attackers access to information that could be useful for account takeover.

The operation also uses Ethereum smart contracts as dead-drop resolvers, allowing attackers to dynamically retrieve infrastructure addresses and payload locations without hard-coding everything into the malware. Elastic says this blockchain-based approach was introduced during the campaign’s 2026 evolution.

1,515 infected systems were identified

Elastic registered one of the campaign’s network-canary domains and observed 1,515 infected systems attempting to reach it. More than 98% were located in Brazil, although that figure should not be interpreted as the total number of victims because it reflects the systems observed through that specific telemetry.

The campaign has reportedly gone through seven distinct campaigns, evolving from commodity RAT distribution into a more sophisticated browser-focused credential theft operation. It appears the attackers are continuing to adapt their infrastructure and evasion techniques.

For Chrome and Edge users, the case is another reminder that malicious extensions do not always require a victim to knowingly install something from an official extension store.

More about the topics: Cybersecurity, malware, online banking

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages