HackerFeeds

CyberSecurity News

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News
· September 15, 2026

AI summary

Researchers have discovered a Brazilian banking malware operation that uses a toolkit called KREMLIN to steal credentials and session tokens. The operation has been active since at least May 2025 and involves lures that impersonate multiple Brazilian banks. The threat actor installs a malicious browser extension on Google Chrome and Microsoft Edge. The malware operation is being tracked by Elastic Security Labs under the designation REF9334. The malicious extension allows the attackers to hijack the browsers and steal sensitive information. The operation targets users in Brazil, using fake bank websites to trick them into installing the malware.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.