Executive Summary
The KREMLIN banking malware operation, tracked as REF9334, has been targeting Brazilian financial institutions since May 2025 through sophisticated browser hijacking techniques. The threat actors deploy malicious Chrome and Microsoft Edge extensions that bypass Chromium integrity mechanisms by manipulating Secure Preferences files and regenerating required HMACs. The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, making disruption extremely difficult. Over 1,515 infected systems have been identified, with 98% located in Brazil.
This incident represents the growing sophistication of banking malware that exploits browser extension ecosystems and blockchain infrastructure for resilient operations. As financial institutions increasingly rely on web-based services and multi-factor authentication through browsers, attackers are adapting with advanced techniques that bypass traditional security controls.
Why This Matters Now
Browser-based attacks are escalating as threat actors weaponize extension ecosystems to bypass modern security controls, with similar techniques recently adopted by APT31 and other state-sponsored groups, making this a critical emerging threat vector.
Attack Path Analysis
KREMLIN banking malware begins with JavaScript files masquerading as banking documents that victims manually execute. The malware establishes persistence through scheduled tasks and uses DLL sideloading via legitimate SentinelOne binaries. It installs malicious Chrome/Edge extensions using integrity bypass techniques, then establishes WebSocket communication with C2 servers using Ethereum smart contracts for infrastructure concealment. The extension harvests credentials, session tokens, cookies, and browser data through extensive API access. Finally, stolen banking credentials and session data enable unauthorized financial transactions and account takeovers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims manually execute JavaScript files disguised as banking documents, invoices, or company files, leading to multi-stage loader execution with sandbox evasion checks
MITRE ATT&CK® Techniques
Malicious File
Registry Run Keys / Startup Folder
DLL Side-Loading
Browser Extensions
Credentials from Web Browsers
Screen Capture
Exfiltration Over C2 Channel
Dead Drop Resolver
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Software platforms and applications
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
KREMLIN banking malware directly targets Brazilian banks through credential theft, session hijacking, and browser extension manipulation, compromising customer authentication systems.
Financial Services
Multi-stage JavaScript loaders and blockchain-based C2 infrastructure enable persistent financial data exfiltration, bypassing traditional security controls and compliance frameworks.
Computer Software/Engineering
Malicious browser extensions exploit Chromium integrity mechanisms and developer tools, requiring enhanced application security controls and zero-trust segmentation capabilities.
Information Technology/IT
Campaign demonstrates advanced anti-sandbox evasion and encrypted traffic exploitation, necessitating improved threat detection, anomaly response, and egress security implementations.
Sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokenshttps://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.htmlVerified
- Malicious Browser Extension: KREMLIN Banking Malware - Elastic Security Labshttps://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malwareVerified
- The Phantom Extension: Backdooring Chrome Through Uncharted Pathwayshttps://www.synacktiv.com/en/publications/the-phantom-extension-backdooring-chrome-through-uncharted-pathwaysVerified
- Ethereum Smart Contract Address for KREMLIN C2 Infrastructurehttps://etherscan.io/address/0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07bVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain KREMLIN malware's lateral movement and C2 communication through segmented network access and controlled egress policies. The malware's ability to traverse browser profiles and establish persistent C2 channels would be significantly limited by identity-aware segmentation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise scope would likely be contained to isolated network segments, limiting the malware's ability to immediately access broader cloud workloads and services.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely face restricted access to adjacent workloads and services, reducing the malware's ability to expand its operational footprint across segmented environments.
Control: East-West Traffic Security
Mitigation: Cross-profile and cross-browser lateral movement would likely be constrained by east-west traffic inspection, limiting the malware's ability to traverse network segments and access additional resources.
Control: Multicloud Visibility & Control
Mitigation: C2 communication establishment would likely face visibility constraints and controlled access policies, limiting the malware's ability to maintain persistent command channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely encounter egress policy restrictions, constraining the volume and frequency of sensitive data transmission to external command infrastructure.
Financial transaction impact would likely be reduced in scope due to constrained data exfiltration and limited C2 communication reliability, though compromised credentials could still pose residual risk.
Impact at a Glance
Affected Business Functions
- Online Banking Services
- Digital Payment Processing
- Customer Authentication Systems
- Financial Transaction Security
Estimated downtime: N/A
Estimated loss: N/A
Banking credentials, session tokens, browser cookies, localStorage and sessionStorage data, browsing history, screenshots of banking sessions, and HTML source code from financial websites across multiple Brazilian banking institutions. Over 1,515 infected systems identified, with 98% located in Brazil.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to detect and block suspicious outbound communications to unknown C2 domains and cryptocurrency-related traffic patterns
- • Deploy Zero Trust Segmentation with least privilege policies to prevent browser extension abuse and limit access to sensitive browser APIs and storage locations
- • Enable Multicloud Visibility & Control to detect anomalous browser behavior, suspicious automation patterns, and unauthorized extension installations across endpoints
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal browser traffic patterns and alert on suspicious WebSocket connections and cryptocurrency smart contract queries
- • Implement Encrypted Traffic (HPE) inspection to analyze and detect malicious payloads hidden in seemingly legitimate file downloads and browser extension communications



