Find notable cyber news and cases, enriched with sources, timelines, and signals.

KREMLIN browser-extension credential theft activity

Malware Activity
First reported
Last updated
Happening score
H score 44
2 unique sources, 2 articles

Summary

Hide ▲

The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive browser data. Elastic Security Labs said the loader bypasses Chromium integrity checks, installs the extension without user approval, and uses Ethereum smart contracts and Internet Archive-hosted payloads to rotate infrastructure and deliver the chain. The activity spans seven campaigns, impersonates 12 banks, and includes recent use of REMCOS or Pulsar RAT alongside the browser-extension theft. Elastic also confirmed 1,515 infected systems, almost all in Brazil, and disrupted the current campaign by registering an anti-sandbox canary domain.

Related Happenings

REF9334 Brazilian bank lure campaign using malicious browser extensions

Campaign
H score51 First: 15.09.2026 21:54 Last: 15.09.2026 21:54 Sources 1

How related: "Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."

About this happening: The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....

JSCeal malware activity

Malware Activity
H score29 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

About this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...

Malicious Chrome and Edge browser-extension campaign

Campaign
H score16 First: 30.08.2026 17:17 Last: 30.08.2026 17:17 Sources 1

About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...

Superior malicious extension installation campaign

Campaign
H score17 First: 28.08.2026 18:27 Last: 28.08.2026 18:27 Sources 1

About this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

Timeline

  1. 16.09.2026 21:50 1 articles · 5d ago

    Elastic disrupts KREMLIN campaign and confirms 1,515 infections

    Mitigation Patch Update

    Elastic Security Labs registered a domain used as an anti-sandbox canary to break the KREMLIN loader, and confirmed 1,515 infected systems, almost all in Brazil.

    Show sources
  2. 15.09.2026 21:54 1 articles · 6d ago

    KREMLIN moves endpoint rotation to Ethereum smart contracts

    Technical Analysis Update

    On May 19, 2026, KREMLIN shifted to Ethereum smart contracts to resolve volmira[.]site and zaviro[.]online, allowing the operation to rotate command-and-control endpoints and payload-hosting locations while also retrieving the AVSync System Inc. browser extension version 1.0.0 and ID ndpbidppejfanjbhfgjlohfanbfbklff.

    Show sources
  3. 15.09.2026 21:54 2 articles · 6d ago

    Elastic Security Labs discloses REF9334 banking malware

    Initial Disclosure

    On September 15, 2026, Elastic Security Labs disclosed REF9334, a previously undocumented Brazilian banking malware operation active since at least May 2025 that uses lures impersonating Brazilian banks to install a malicious browser extension on Google Chrome and Microsoft Edge and steal credentials, session tokens, and sensitive data.

    Show sources