KREMLIN browser-extension credential theft activity
Malware Activity
Summary
Hide ▲
Show ▼
The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive browser data. Elastic Security Labs said the loader bypasses Chromium integrity checks, installs the extension without user approval, and uses Ethereum smart contracts and Internet Archive-hosted payloads to rotate infrastructure and deliver the chain. The activity spans seven campaigns, impersonates 12 banks, and includes recent use of REMCOS or Pulsar RAT alongside the browser-extension theft. Elastic also confirmed 1,515 infected systems, almost all in Brazil, and disrupted the current campaign by registering an anti-sandbox canary domain.
Related Happenings
REF9334 Brazilian bank lure campaign using malicious browser extensions
Campaign
H score51
First: 15.09.2026 21:54
Last: 15.09.2026 21:54
Sources 1
How related:
"Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."
About this happening:
The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....
REF9334 Brazilian bank lure campaign using malicious browser extensions
CampaignHow related: "Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."
About this happening: The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....
JSCeal malware activity
Malware Activity
H score29
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
About this happening:
JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
JSCeal malware activity
Malware ActivityAbout this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignAbout this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Superior malicious extension installation campaign
Campaign
H score17
First: 28.08.2026 18:27
Last: 28.08.2026 18:27
Sources 1
About this happening:
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Superior malicious extension installation campaign
CampaignAbout this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Timeline
-
16.09.2026 21:50 1 articles · 5d ago
Elastic disrupts KREMLIN campaign and confirms 1,515 infections
Mitigation Patch UpdateElastic Security Labs registered a domain used as an anti-sandbox canary to break the KREMLIN loader, and confirmed 1,515 infected systems, almost all in Brazil.
Show sources
- Malware bypasses browser checks to force install Chrome, Edge extensions — www.bleepingcomputer.com — 16.09.2026 21:50
-
15.09.2026 21:54 1 articles · 6d ago
KREMLIN spans seven distinct campaigns
Campaign Scope UpdateBy June 16, 2025, the KREMLIN operation had already been attributed to seven distinct campaigns and was using malicious browser extensions alongside off-the-shelf Trojans such as Pulsar RAT and Remcos RAT.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 1 articles · 6d ago
KREMLIN moves endpoint rotation to Ethereum smart contracts
Technical Analysis UpdateOn May 19, 2026, KREMLIN shifted to Ethereum smart contracts to resolve volmira[.]site and zaviro[.]online, allowing the operation to rotate command-and-control endpoints and payload-hosting locations while also retrieving the AVSync System Inc. browser extension version 1.0.0 and ID ndpbidppejfanjbhfgjlohfanbfbklff.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 2 articles · 6d ago
Elastic Security Labs discloses REF9334 banking malware
Initial DisclosureOn September 15, 2026, Elastic Security Labs disclosed REF9334, a previously undocumented Brazilian banking malware operation active since at least May 2025 that uses lures impersonating Brazilian banks to install a malicious browser extension on Google Chrome and Microsoft Edge and steal credentials, session tokens, and sensitive data.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54