KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Medium · The Hacker News ·

What happened

KREMLIN banking malware (REF9334), active since May 2025, uses fake Brazilian bank lures to install malicious Chrome and Edge extensions that steal credentials and session tokens.

What to do now

Enforce Chrome/Edge extension allowlisting and block sideloaded extensions via policy; alert on new extension installs and anomalous session-token activity. Confirm scope with the vendor advisory.

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news