top of page

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials 

2 days ago
2 min read

 

In mid September 2026, cybersecurity research uncovered a Brazilian banking malware operation delivering a complex threat toolkit named KREMLIN. Tracked by researchers as REF9334 and active since at least May 2025, the threat cluster predominantly targets Brazilian financial institutions and banking users through localized lures written in Portuguese. Despite its name, the operation shows no connection to Russian state actors. The core objective of the toolkit is to bypass Chromium security protections to silently plant persistent, data stealing browser extensions on Google Chrome and Microsoft Edge.  


Multi Stage Loader Mechanics and Infrastructure Hiding  

The attack chain begins with a malicious JavaScript file disguised as a legitimate invoice, company record, or banking document that victims manually execute. Upon execution, the initial loader runs extensive anti-sandbox checks, counting active processes, inspecting hardware parameters, and querying a canary domain to detect network simulation environments. To maintain resilient communications, KREMLIN uses Ethereum smart contracts as dead-drop resolvers. This blockchain integration allows operators to dynamically update command and control domains or payload hosting locations without modifying deployed malware components. The infection process also incorporates binary defense evasion, using legitimate SentinelOne executables to sideload malicious DLLs inside trusted system processes.  


Integrity Bypasses and Data Theft Operations  

The defining capability of KREMLIN is its ability to bypass Chromium extension integrity controls without alerting the user. The installer waits for browser processes to close, extracts local encryption keys, and directly modifies the browser Secure Preferences file. By recalculating and forging required cryptographic HMACs and encrypted hashes, the malware forces Chrome and Edge to accept rogue, locally loaded extensions named AVSync System Inc as fully verified add-ons. Once active, the rogue extension requests broad permissions across browser tabs, cookies, storage APIs, and web requests to systematically harvest login credentials, active session tokens, and financial data for exfiltration to attacker infrastructure. To counter these threats, security teams must deploy endpoint agents capable of detecting unauthorized browser preference file modifications, restrict developer mode capabilities via group policy, and monitor process creation originating from unverified script engines.  


Reference

 
 
 

Comments


Address: Office B322, Level 3, Spaces, Platinum Sentral, KL Sentral, 50470 Kuala Lumpur.

  • Facebook
  • Instagram
  • LinkedIn

Hotline+60327224705

© 2025 Vardaan Sdn Bhd. All Rights Reserved.

bottom of page