Home / Sep 16, 2026 / Story
0
#10 The Hacker News general September 15, 2026 at 18:54 UTC

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

By [email protected] (The Hacker News)

AI Summary

Elastic Security Labs identified a Brazilian banking malware operation tracked as REF9334, active since at least May 2025, delivering a toolkit called KREMLIN that installs malicious browser extensions on Google Chrome and Microsoft Edge to steal credentials and session tokens from users of approximately a dozen Brazilian banks. The MaaS-style operation's use of browser extension hijacking to bypass credential protections represents a growing threat vector for financial sector defenders in Latin America and beyond.

Relevance score: 80.0/100

# More from September 16