Executive Summary

The KREMLIN banking malware operation, tracked as REF9334, has been targeting Brazilian financial institutions since May 2025 through sophisticated browser hijacking techniques. The threat actors deploy malicious Chrome and Microsoft Edge extensions that bypass Chromium integrity mechanisms by manipulating Secure Preferences files and regenerating required HMACs. The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, making disruption extremely difficult. Over 1,515 infected systems have been identified, with 98% located in Brazil.

This incident represents the growing sophistication of banking malware that exploits browser extension ecosystems and blockchain infrastructure for resilient operations. As financial institutions increasingly rely on web-based services and multi-factor authentication through browsers, attackers are adapting with advanced techniques that bypass traditional security controls.

Why This Matters Now

Browser-based attacks are escalating as threat actors weaponize extension ecosystems to bypass modern security controls, with similar techniques recently adopted by APT31 and other state-sponsored groups, making this a critical emerging threat vector.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

KREMLIN uses the Phantom Extension technique to modify Secure Preferences files, enable developer mode, and forge metadata in the protection.macs JSON object to register malicious extensions without triggering security warnings.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain KREMLIN malware's lateral movement and C2 communication through segmented network access and controlled egress policies. The malware's ability to traverse browser profiles and establish persistent C2 channels would be significantly limited by identity-aware segmentation.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise scope would likely be contained to isolated network segments, limiting the malware's ability to immediately access broader cloud workloads and services.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation attempts would likely face restricted access to adjacent workloads and services, reducing the malware's ability to expand its operational footprint across segmented environments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-profile and cross-browser lateral movement would likely be constrained by east-west traffic inspection, limiting the malware's ability to traverse network segments and access additional resources.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communication establishment would likely face visibility constraints and controlled access policies, limiting the malware's ability to maintain persistent command channels across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely encounter egress policy restrictions, constraining the volume and frequency of sensitive data transmission to external command infrastructure.

Impact (Mitigations)

Financial transaction impact would likely be reduced in scope due to constrained data exfiltration and limited C2 communication reliability, though compromised credentials could still pose residual risk.

Impact at a Glance

Affected Business Functions

  • Online Banking Services
  • Digital Payment Processing
  • Customer Authentication Systems
  • Financial Transaction Security
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Banking credentials, session tokens, browser cookies, localStorage and sessionStorage data, browsing history, screenshots of banking sessions, and HTML source code from financial websites across multiple Brazilian banking institutions. Over 1,515 infected systems identified, with 98% located in Brazil.

Recommended Actions

  • Implement Egress Security & Policy Enforcement to detect and block suspicious outbound communications to unknown C2 domains and cryptocurrency-related traffic patterns
  • Deploy Zero Trust Segmentation with least privilege policies to prevent browser extension abuse and limit access to sensitive browser APIs and storage locations
  • Enable Multicloud Visibility & Control to detect anomalous browser behavior, suspicious automation patterns, and unauthorized extension installations across endpoints
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal browser traffic patterns and alert on suspicious WebSocket connections and cryptocurrency smart contract queries
  • Implement Encrypted Traffic (HPE) inspection to analyze and detect malicious payloads hidden in seemingly legitimate file downloads and browser extension communications

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image