KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Medium · The Hacker News ·
What happened
KREMLIN banking malware (REF9334), active since May 2025, uses fake Brazilian bank lures to install malicious Chrome and Edge extensions that steal credentials and session tokens.
What to do now
Enforce Chrome/Edge extension allowlisting and block sideloaded extensions via policy; alert on new extension installs and anomalous session-token activity. Confirm scope with the vendor advisory.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.