tech-briefing · · 2 min read

New Brazilian Banking Malware Targets Chrome and Edge Browsers

By [email protected] (The Hacker News)

New Brazilian Banking Malware Targets Chrome and Edge Browsers

Sophisticated Data Extraction Tactics

Security researchers have identified a sophisticated new banking malware campaign originating from Brazil. Known as KREMLIN, the toolkit has been actively stealing sensitive credentials and session tokens from Google Chrome and Microsoft Edge users since May 2025. Experts at Elastic Security Labs are currently tracking this malicious operation under the designation REF9334.

The threat actors behind this campaign utilize deceptive lures to trick victims into installing the malware. Once the malicious software gains a foothold on a system, it systematically harvests browser data. By hijacking active sessions, attackers can bypass traditional security measures, effectively impersonating legitimate users to access protected financial accounts and private information.

The KREMLIN toolkit is specifically engineered to interface with popular web browsers. It focuses on exfiltrating authentication cookies and login credentials stored within the browser environment. This approach allows cybercriminals to maintain persistent access to victim accounts even if passwords are changed or multi-factor authentication is enabled.

How Can Users Protect Their Digital Assets?

The malware operates silently in the background, minimizing its footprint to avoid detection by standard antivirus programs. By targeting the browser’s internal storage, the attackers ensure they capture the most valuable data needed for illicit financial transfers. This level of precision indicates a highly organized group with a deep understanding of browser architecture.

Defending against such threats requires a proactive approach to browser security. Users should avoid clicking on suspicious links or downloading unsolicited attachments that often serve as the initial delivery vector for KREMLIN. Regularly clearing browser cache and session tokens can also limit the window of opportunity for attackers attempting to hijack active connections.

Frequently Asked Questions

The emergence of KREMLIN highlights the growing sophistication of banking trojans targeting browser-based data. As these criminals refine their methods, the risk to individual and corporate financial security continues to rise. Staying informed about current phishing trends remains the most effective defense against these evolving digital threats.

What does the KREMLIN malware actually steal? It primarily targets stored login credentials and active session tokens from web browsers. This data allows attackers to hijack user accounts and bypass standard security protocols.

Can antivirus software stop this threat? While security tools can detect some components, the malware is designed to operate stealthily. Users should rely on cautious browsing habits as their primary line of defense.

More stories:

Content written by [email protected] (The Hacker News) for techbriefe.com editorial team, AI-assisted.

Share:

Leave a comment