NewsTradingSentimentCalendarCommunityBriefing
Tech

Brazilian Malware Hijacks Browsers to Steal Banking Sessions

By Tech Desk · 2026-09-15 · 1 min read
A sleek metallic digital padlock with a keyhole against a dark background.
Illustration: Tradingbird

Researchers uncovered a new malware operation that forces Chrome and Edge to accept malicious extensions, bypassing security checks to steal sensitive financial data.

A previously undocumented malware campaign targeting Brazilian bank customers has been identified by security researchers. The operation, dubbed KREMLIN, actively manipulates Google Chrome and Microsoft Edge to install unauthorized extensions. These additions allow attackers to intercept login credentials and session tokens, effectively giving them control over victims' online banking activities without their knowledge.

The threat actor, tracked as REF9334, has been active since at least May 2025. According to a report shared with The Hacker News, the malware uses deceptive files disguised as invoices or bank documents to initiate the infection. Once executed, the software installs a toolkit that harvests sensitive data and exfiltrates it to remote servers, leaving little trace for standard security tools to detect.

Browsers forced to accept malicious code

The core of the attack relies on a technical weakness in how Chromium-based browsers verify extensions. The malware modifies internal security files to forge the metadata required for legitimate software. This allows the malicious extension, named

Using blockchain to hide command centers

To avoid detection and disruption, the attackers use Ethereum smart contracts as a communication channel. Instead of using traditional servers that can be easily blocked, the malware queries these blockchain contracts to find the current location of its command-and-control infrastructure. This dynamic approach makes it significantly harder for defenders to track and shut down the operation, as the endpoints change frequently based on the smart contract data.

Evasion techniques target security analysts

The malware includes specific checks to ensure it is running on a real user device rather than a sandbox or virtual machine used by security researchers. It scans for specific processes and hardware specifications, such as CPU count and RAM capacity. If the environment matches known analysis setups, the malware terminates itself. Additionally, it abuses a legitimate security tool binary to load its malicious components, further complicating detection efforts for organizations relying on standard signature-based defenses.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A large, windowless industrial building with rows of ventilation fans on the side, standing in a suburban landscape
    Illustration: Tradingbird

    Poway Council Prepares Ban on AI Data Centers

    A small California city is moving to block the construction of artificial intelligence facilities, citing severe risks to local water supplies, power grids, and air quality. This decision represents a significant shift in how communities are managing the physical footprint of the digital economy.

    2026-09-15
  • A sleek white electric aircraft parked on a tarmac next to a large industrial charging station with thick cables coiled neatly on the ground.
    Illustration: Tradingbird

    Texas Leads Push for Shared Electric Air Taxi Charging Network

    A new consortium aims to standardize charging infrastructure for electric air taxis across major Texas airports, seeking to solve the fragmentation problem in eVTOL support systems.

    2026-09-15
  • A heavy iron padlock resting on a polished wooden desk surface
    Illustration: Tradingbird

    Treasury Rejects AI Liability Waivers

    Treasury Secretary Scott Bessent urged lawmakers to reject requests from AI developers for legal immunity, arguing that holding creators accountable is the most effective way to ensure technological safety.

    2026-09-15