$ techbeacon▋
Phishing

Brazilian Banking Malware ‘KREMLIN’ Hijacks Chrome and Edge to Capture Login Data

Brazilian Banking Malware ‘KREMLIN’ Hijacks Chrome and Edge to Capture Login Data

Cybersecurity researchers have identified a new banking malware suite, dubbed KREMLIN, that covertly takes control of Chrome and Edge browsers to harvest user credentials and active session tokens.

The toolkit, first observed in May 2025, is tracked by Elastic Security Labs under the reference REF9334. Analysts describe the operation as previously undocumented, emerging from a Brazilian threat actor that has refined delivery mechanisms to bypass conventional defenses.

KREMLIN operates by injecting malicious code into the browser process, allowing it to intercept form submissions and extract authentication cookies. The stolen data is then relayed to command‑and‑control servers, where it can be used to impersonate victims and initiate unauthorized transactions.

The discovery arrives amid a surge of financial malware targeting South America, where banks have long been prime targets for cyber‑crime. Earlier strains focused on keyloggers or mobile trojans; KREMLIN’s focus on desktop browsers marks a shift toward exploiting the most widely used access points for online banking.

While the full scope of compromised accounts remains unclear, security firms warn that the malware’s ability to mimic legitimate browser traffic makes detection difficult. Financial institutions are urged to monitor for anomalous login patterns and to deploy behavioral analytics that can flag compromised sessions.

Researchers recommend that users keep browsers and security software up to date, avoid downloading files from untrusted sources, and consider multi‑factor authentication where available. Ongoing surveillance by groups like Elastic Security Labs will track the evolution of KREMLIN, with expectations that the threat actor may adapt the toolkit to target additional browsers or expand its geographic reach.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related