REF9334 Uses KREMLIN Toolkit to Hit Brazilian Banks via Browser Extensions

Medium · The Hacker News ·

Key points

  • REF9334 has targeted roughly twelve Brazilian banks since May 2025.
  • The KREMLIN toolkit helps deploy a harmful extension in Chrome and Edge.
  • Elastic Security Labs, Google, and Microsoft are linked to the research or affected platforms.
  • The campaign steals credentials, session tokens, and control of browser sessions.
  • No CVE is associated; defenses should focus on extension controls and token protection.

A financially motivated group called REF9334 is running a Brazil-oriented banking malware scheme. Since May 2025, it has posed as financial brands to trick users into adding a harmful extension to Chrome or Edge. The KREMLIN toolkit underpins the operation, according to Elastic Security Labs, with Google and Microsoft relevant to the browser and platform ecosystem.

The campaign has touched about a dozen banks in Brazil. Customers of those institutions are primary targets, but any organization whose staff use Chrome or Edge could face follow-on risk if credentials or session cookies are lifted.

The intrusion path does not rely on a software vulnerability; no CVE is tied to it. Instead, it abuses trust and browser extension permissions. Once installed, the add-on can harvest usernames and passwords, exfiltrate authentication tokens, and take over browsing sessions, enabling account access even when passwords change or MFA is partially satisfied.

Browser-focused banking trojans are attractive because they sit where users log in and where session tokens live. The KREMLIN toolkit lowers the barrier for deploying extensions that blend into normal browsing. REF9334's activity since May 2025 suggests an ongoing, adaptable campaign rather than a short burst.

Watch for unexpected extension installs, new permissions on Chrome or Edge, and logins from unusual locations. Security teams should monitor for token replay and impossible-travel alerts, especially for finance and treasury users. Elastic Security Labs, Google, and Microsoft advisories may provide additional indicators as the operation evolves.

What to do now

  1. Block or allowlist browser extensions by policy in Chrome and Edge; require admin approval for new installs.
  2. Force reauthentication and revoke active sessions or tokens for any user suspected of exposure; rotate credentials.
  3. Enable phishing-resistant MFA where possible and monitor for token replay or anomalous session use.
  4. Deploy endpoint detection for KREMLIN toolkit indicators and extension installation behavior; hunt for REF9334 artifacts.
  5. Educate finance and banking users about brand impersonation and unexpected extension prompts.
  6. Review browser logs, extension inventories, and proxy or DNS records for connections to known malicious domains.
  7. Apply browser and OS updates, though no CVE is involved, to reduce adjacent attack surface.

Original source

The Hacker News

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news