KREMLIN is a Brazil-focused banking trojan and browser-data theft toolkit associated with the REF9334 cybercriminal operation. Active since at least May 2025, it has primarily targeted Brazilian users through Portuguese-language lures impersonating banks, payment services, invoices, receipts, and corporate documents. Infection begins when a victim manually executes a malicious JavaScript document, after which staged loaders and custom installers deploy additional components.
KREMLIN establishes Windows persistence through scheduled tasks, performs sandbox and virtual-machine checks, and uses Ethereum smart contracts as dead-drop resolvers for mutable payload-hosting and command-and-control configuration. Later activity abused a legitimate SentinelOne component for DLL side-loading. The toolkit silently installs malicious AVSync browser extensions in Google Chrome and Microsoft Edge, bypassing Chromium extension-integrity protections through the Phantom Extension technique, including manipulation of protected browser preferences and integrity metadata.
The malicious extensions can steal saved credentials, cookies, session and local storage, browser databases, browser encryption keys, typed form data, page content, screenshots, tab information, and browser history. They also support keylogging, interception of web requests, HTML injection, click redirection, and remote command-and-control communications. Theft of browser cookies and session tokens can permit authenticated-session hijacking and account takeover, particularly against online banking and cryptocurrency services. Earlier and related campaigns also distributed Pulsar RAT and Remcos RAT. Observed victim telemetry indicates that the overwhelming majority of identified infections were in Brazil.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Elastic Security Labs describes REF9334 as a Brazilian banking-malware operation active since May 2025. The toolkit is named KREMLIN by its author, Kr3mlin4rt1st, and deploys a malicious Chromium extension while using Node.js, scheduled-task persistence, DLL sideloading, and Ethereum smart contracts for configuration and payload delivery.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Для хранения полезных нагрузок хакеры также использовали Internet Archive, скрывая малварь внутри изображений JPEG.
TTPs détectés : T1027.007 — Obfuscated Files or Information: Dynamic API Resolution.
TTPs détectés : T1027.013 — Obfuscated Files or Information: Encrypted/Encoded File.
Заражение начинается с файла JavaScript, который маскируется под банковскую квитанцию, счет, платежный документ или другой корпоративный файл.
Les fichiers JavaScript utilisent des noms en portugais (COMPROVANTE, Extrato, PIX).
TTPs détectés : T1140 — Deobfuscate/Decode Files or Information.
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
После установки вредоносное расширение похищает файлы cookie, содержимое localStorage и sessionStorage... Сам KREMLIN тоже ... может похищать ... файлы cookie.
Le malware débogue le processus Chrome et lit sa mémoire.
Vol de cookies/sessionStorage/localStorage; lecture mémoire via ReadProcessMemory.
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
“[KREMLIN] retrieves fresh hosting details from an Ethereum smart contract.”
“[KREMLIN] retrieves fresh hosting details from an Ethereum smart contract.”
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware operation referenced only as a comparison for browser-extension-based credential and two-factor-authentication-code theft.
Banking malware mentioned only as a comparison for browser-extension-based credential and two-factor authentication code theft.
Brazil-focused banking malware and infostealer active since at least May 2025. It uses a multi-stage JavaScript-led loader, persistence through Scheduled Tasks, and Ethereum smart-contract-hosted payload addresses. It bypasses Chromium Secure Preferences integrity checks to silently install the AVSync extension, then steals credentials, cookies, session tokens, browser data, App-Bound keys, and other user information.
A Brazil-focused banking-malware operation that uses malicious Chrome and Edge extensions to steal passwords, session cookies, browser databases, encryption keys, typed text, screenshots, and other browser data. It uses JavaScript lures, sandbox checks, scheduled-task persistence, Ethereum smart-contract-based configuration retrieval, and browser-preference tampering to force-install extensions outside official stores.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.