SecurityUnverified

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

What happened

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

Why it matters

The development may change operating conditions or market expectations around Google. Further confirmation and measurable outcomes matter.

Affected entities

Google · GOOGLNeutral

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Claims

  • KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude45
Market relevance74
Entity significance92
Market breadth54
Novelty68
Urgency55
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.9994
Breaking bonus0