Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > KREMLIN Banking Malware Targets Brazilian Users with Malicious Browser Extension

KREMLIN Banking Malware Targets Brazilian Users with Malicious Browser Extension

By: Morgan Cipher — Senior Privacy Journalist

Last updated: September 17, 2026

Human Written
KREMLIN Banking Malware Targets Brazilian Users with Malicious Browser Extension
  • KREMLIN has targeted Brazilian bank customers in seven separate attacks since at least May 2025.

  • The malware sneaks in a fake browser extension that grabs cookies, session info, page details, and other private data.

  • The campaign does not depend on fixed addresses; rather, it utilizes the Ethereum smart contract to facilitate the malware delivery and locate new command servers.

A study has found a banking malware campaign that utilizes a fake Chrome or Edge browser extension to target Brazilian users. Elastic Security Labs calls the malware KREMLIN and tracks the wider activity as REF9334. The campaign has used files that look like bank documents, invoices, or business files.

Once a victim runs the fake file, KREMLIN starts a malware chain that ends with a rogue Chrome or Edge add-on.

How the KREMLIN Attack Starts

The first stage is a JavaScript file. The victim must run it by hand. The script checks the computer before it moves on. It looks for signs of a virtual machine or a test system. If it finds signs of analysis, it can stop the attack.

On a normal system, it downloads more files. The next stage includes a C++ installer, a .NET injector, and a real SentinelOne program called SentinelMemoryScanner.exe.

KREMLIN abuses that SentinelOne file to load a bad DLL. The DLL uses the name SentinelAgentCore.dll to look like a real SentinelOne file. It checks running programs and basic hardware details. These checks include the number of CPUs and the amount of memory.

A Fake Browser Add-on Gets Installed

The key part of the attack is the malicious browser add-on. KREMLIN changes Chrome’s Secure Preferences file. Chrome uses this file to protect key add-on settings.

The malware also creates the checks Chrome uses to spot changes to that file. This lets it add the rogue extension without setting off the normal protection. Researchers link this method to a public technique called Phantom Extension. A related method is known as GhostChrome-X.

The add-on is called AVSync System Inc. One sample had the ID ndpbidppejfanjbhfgjlohfanbfbklff.

KREMLIN is not the only campaign abusing browser extensions to target users. Researchers have also uncovered malicious Firefox extensions that disguise themselves as crypto wallets, putting users’ cryptocurrency and wallet credentials at risk.

KREMLIN checks whether the add-on is already on the system. If it is missing or an old version is present, the malware downloads a new copy.

What the Add-on can Steal

After installation, the add-on connects to the attackers’ server. It can list open tabs and collect details about active pages. It can also steal cookies, sessionStorage, and localStorage from selected pages. That data can expose active web sessions and other information stored by websites.

The add-on can take screenshots and collect the full HTML code of an open page. It can also receive HTML from the attackers. Researchers found code that tries to collect up to 1,000 history entries from the past 15 days. Elastic said this may fail because the add-on lacks the needed history permission.

The malware also sends requests that look like CSS files. Different names trigger data theft, screenshots, page collection, or new rules.

Ethereum Helps Hide the Changing Servers

KREMLIN also uses Ethereum in an unusual way. The malware reads an Ethereum smart contract. It uses it to find download sites and command servers. The setup acts like a public list of addresses for the malware. Attackers can update those sites without having to change the malware file.

As per reports from Elastic, this campaign started exploiting Ethereum smart contracts on May 19, 2026. They’ve observed seven such campaigns since June 16, 2025. The group has also spread Pulsar RAT and Remcos RAT.

Elastic Found 1,515 Infected Systems

Elastic also found a way to disrupt one KREMLIN check. The malware tries to contact an unregistered domain as a network test. It expects the domain not to respond.

The researchers registered that domain. They then saw 1,515 infected systems try to contact it. More than 98% of those systems were geolocated to Brazil. The move did not remove KREMLIN from those machines. It disrupted one check and may give defenders more time to clean infected systems.

Why the Campaign Matters

KREMLIN shows how banking malware is moving deeper into the browser. A stolen password is not the only prize. Cookies and browser data can expose active sessions.

The campaign also shows why browser add-ons need close attention. An add-on with broad access can see much of what happens inside a browser. For users, the warning is simple. Do not run JavaScript files sent as invoices or bank notices. Only open them when the source is trusted, and the file is expected.

Security teams can watch for unknown add-ons, browser file changes, new tasks, and odd browser traffic. The KREMLIN campaign also shows why defenders need to watch the browser itself, not just the files running on a computer.

Share this article

You might also like

Paris Man Accused of Hacking Police and Court Systems to Defraud Notaries

Paris Man Accused of Hacking French Police and Justice Servers in €1 Million Fraud Scheme

A 25-year-old man in Paris allegedly hacked police and court computer systems to launch a scam. He posed as police…

September 15, 2026
China-Linked Hackers Exploit Sogou Input Method Flaw to Deploy Backdoor

China-Linked Hackers Exploit Critical Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

UNC3569 exploited CVE-2026-51990 in Sogou Input Method to gain code execution through a specially crafted sgbiz: link. The attack abused…

September 15, 2026
Microsoft Warns of AI-Powered Payment Scams and Passkey Phishing Attacks

Microsoft Warns of AI-Assisted Payment Fraud and Passkey Phishing Campaigns

Microsoft disclosed details on two cyber operations involving AI-generated executive payment scams and phone-based passkey phishing schemes targeting corporate accounts.…

September 15, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.