CyberSecurity News
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
AI summary
Researchers have discovered a Brazilian banking malware operation that uses a toolkit called KREMLIN to steal credentials and session tokens. The operation has been active since at least May 2025 and involves lures that impersonate multiple Brazilian banks. The threat actor installs a malicious browser extension on Google Chrome and Microsoft Edge. The malware operation is being tracked by Elastic Security Labs under the designation REF9334. The malicious extension allows the attackers to hijack the browsers and steal sensitive information. The operation targets users in Brazil, using fake bank websites to trick them into installing the malware.
Countries in focus
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

