negativeSYS.SOURCE: The Hacker News• 2026-09-16T00:24:14+05:30
KREMLIN Banking Malware Exploits Chrome and Edge to Steal Credentials via Ethereum-Driven C2
KREMLIN banking malware targets Chrome and Edge by deploying malicious extensions that bypass security via Ethereum smart contracts, stealing credentials and session tokens. It employs multi-stage loaders, sandbox evasion, and blockchain-based C2 infrastructure to maintain persistence and exfiltrate data.
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.
Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
*** END OF TRANSMISSION ***