KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News · Sep 16, 2026

Back to News
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Security September 16, 2026

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.