KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
- ID
- 24821
- Status
- summarized
- Published
- 16 Sep 2026, 2:54 AM
- Fetched
- 16 Sep 2026, 3:50 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 16 Sep 2026, 3:54 AM
- Tags
- Audience
- developers
What happened
Elastic Security Labs detailed a Brazilian banking malware operation (REF9334) using a toolkit called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions impersonating a dozen Brazilian banks. The malware bypasses Chromium integrity mechanisms by manipulating Secure Preferences and regenerating HMACs, uses Ethereum smart contracts as dead drop resolvers for C2 endpoints, and sideloads its payload via a legitimate SentinelOne binary.
Why it matters
The technique of bypassing Chromium's extension integrity checks by regenerating HMACs and manipulating Secure Preferences is worth noting if you build or secure browser-based products, but this campaign targets Brazilian bank customers specifically and has no direct impact on Malaysian or SEA builders. No action required unless you work in browser security or anti-fraud.
Discussion angle
The use of Ethereum smart contracts as C2 dead drop resolvers is a notable evolution in infrastructure resilience — worth a brief mention as an example of how attackers are adopting blockchain for takedown resistance, but not actionable for most builders.