Brazilian Malware Hijacks Browsers to Steal Banking Sessions

Researchers uncovered a new malware operation that forces Chrome and Edge to accept malicious extensions, bypassing security checks to steal sensitive financial data.
A previously undocumented malware campaign targeting Brazilian bank customers has been identified by security researchers. The operation, dubbed KREMLIN, actively manipulates Google Chrome and Microsoft Edge to install unauthorized extensions. These additions allow attackers to intercept login credentials and session tokens, effectively giving them control over victims' online banking activities without their knowledge.
The threat actor, tracked as REF9334, has been active since at least May 2025. According to a report shared with The Hacker News, the malware uses deceptive files disguised as invoices or bank documents to initiate the infection. Once executed, the software installs a toolkit that harvests sensitive data and exfiltrates it to remote servers, leaving little trace for standard security tools to detect.
Browsers forced to accept malicious code
The core of the attack relies on a technical weakness in how Chromium-based browsers verify extensions. The malware modifies internal security files to forge the metadata required for legitimate software. This allows the malicious extension, named
Using blockchain to hide command centers
To avoid detection and disruption, the attackers use Ethereum smart contracts as a communication channel. Instead of using traditional servers that can be easily blocked, the malware queries these blockchain contracts to find the current location of its command-and-control infrastructure. This dynamic approach makes it significantly harder for defenders to track and shut down the operation, as the endpoints change frequently based on the smart contract data.
Evasion techniques target security analysts
The malware includes specific checks to ensure it is running on a real user device rather than a sandbox or virtual machine used by security researchers. It scans for specific processes and hardware specifications, such as CPU count and RAM capacity. If the environment matches known analysis setups, the malware terminates itself. Additionally, it abuses a legitimate security tool binary to load its malicious components, further complicating detection efforts for organizations relying on standard signature-based defenses.






