AI Weekly Malaysia

Back to items Summaries

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

ID
24821
Status
summarized
Published
16 Sep 2026, 2:54 AM
Fetched
16 Sep 2026, 3:50 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
16 Sep 2026, 3:54 AM
Tags
Audience
developers

What happened

Elastic Security Labs detailed a Brazilian banking malware operation (REF9334) using a toolkit called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions impersonating a dozen Brazilian banks. The malware bypasses Chromium integrity mechanisms by manipulating Secure Preferences and regenerating HMACs, uses Ethereum smart contracts as dead drop resolvers for C2 endpoints, and sideloads its payload via a legitimate SentinelOne binary.

Why it matters

The technique of bypassing Chromium's extension integrity checks by regenerating HMACs and manipulating Secure Preferences is worth noting if you build or secure browser-based products, but this campaign targets Brazilian bank customers specifically and has no direct impact on Malaysian or SEA builders. No action required unless you work in browser security or anti-fraud.

Discussion angle

The use of Ethereum smart contracts as C2 dead drop resolvers is a notable evolution in infrastructure resilience — worth a brief mention as an example of how attackers are adopting blockchain for takedown resistance, but not actionable for most builders.

Top