#10
The Hacker News
general
September 15, 2026 at 18:54 UTC
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
By [email protected] (The Hacker News)
AI Summary
Elastic Security Labs identified a Brazilian banking malware operation tracked as REF9334, active since at least May 2025, delivering a toolkit called KREMLIN that installs malicious browser extensions on Google Chrome and Microsoft Edge to steal credentials and session tokens from users of approximately a dozen Brazilian banks. The MaaS-style operation's use of browser extension hijacking to bypass credential protections represents a growing threat vector for financial sector defenders in Latin America and beyond.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →