Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT Vendor NewsElastic

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News, Tuesday, September 15th, 2026

The Hacker News reports that Elastic Security Labs uncovered KREMLIN, a Brazilian banking malware toolkit hijacking Chrome and Edge.

Elastic Security Labs disclosed a Brazilian banking malware operation it tracks as REF9334, active since May 2025 and built around a toolkit named KREMLIN. The chain combines multi-stage JavaScript loaders, custom C++ installers and malicious browser extensions, and uses Ethereum smart contracts as command-and-control resolvers so operators can rotate endpoints without losing access.

The installer defeats Chrome's Secure Preferences integrity protection via a Phantom Extension technique, side-loading an extension that lifts cookies, session tokens, localStorage and sessionStorage.

Elastic counted 1,515 infected systems, over 98 percent in Brazil, and disrupted the campaign by registering a canary domain.

more →  ·  More from Elastic →