Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
![]()

