KREMLIN Banking Malware Hijacks Chromium Browsers
Score: 9/10

KREMLIN Banking Malware Hijacks Chromium Browsers

The REF9334 threat group utilizes the KREMLIN toolkit to install malicious browser extensions on Chrome and Edge, leveraging Ethereum smart contracts as dead-drop resolvers to target Brazilian banking users.

Executive Summary

Elastic Security Labs has identified a sophisticated Brazilian banking malware operation tracked as REF9334, active since at least May 2025. The campaign delivers a toolkit named KREMLIN that primarily targets financial institutions in Brazil by impersonating local banks through malicious JavaScript lures. The threat actor demonstrates advanced technical maturity by using Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, ensuring resilience against standard domain-based takedowns.

The attack chain involves multi-stage JavaScript loaders, DLL sideloading of legitimate binaries (such as SentinelOne), and the manual installation of malicious Chromium extensions. These extensions bypass browser integrity mechanisms by manipulating 'Secure Preferences' and regenerating cryptographic HMACs and App-Bound encrypted hashes. This allows the actor to steal session tokens, credentials, and capture real-time user input through keylogging and automated web requests.

This threat is high-priority for financial organizations and regional businesses in Brazil. The group's ability to automate the recovery of browser encryption keys and forge integrity checks represents a significant evolution in banking Trojan tradecraft. To date, over 1,500 systems have been identified as infected, with nearly 99% geolocated to Brazil.

Key Details

Threat Name

KREMLIN Banking Malware

Affects

—

Adversary

REF9334 Other Adversaries and Aliases: APT31

Malware/Tools

KREMLIN, GemStone, Pulsar RAT, Remcos RAT, RunPE, DonutLoader, CASTLESTEALER, PHANTOMPULSE, REVSTEALER

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources