REF9334 Brazilian bank lure campaign using malicious browser extensions
Campaign
Summary
Hide ▲
Show ▼
The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft. The operation has been active since at least May 2025 and uses repeated lure-and-install chains instead of a one-off payload. Its scale is reinforced by telemetry tied to 1,515 infected systems, with more than 98% geolocated to Brazil.
Related Happenings
KREMLIN browser-extension credential theft activity
Malware Activity
H score44
First: 15.09.2026 21:54
Last: 15.09.2026 21:54
Sources 1
How related:
"The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data,"
About this happening:
The KREMLIN malware operation is using malicious browser extensions and multi-stage loaders to steal credentials and session tokens from Chrome and Edge us...
KREMLIN browser-extension credential theft activity
Malware ActivityHow related: "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data,"
About this happening: The KREMLIN malware operation is using malicious browser extensions and multi-stage loaders to steal credentials and session tokens from Chrome and Edge us...
Timeline
-
15.09.2026 21:54 1 articles · 2h ago
REF9334 linked to seven campaigns since June 16, 2025
Attribution UpdateREF9334 has been attributed to seven distinct campaigns since June 16, 2025, including malicious browser-extension activity and distribution of off-the-shelf Trojans such as Pulsar RAT and Remcos RAT.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 1 articles · 2h ago
KREMLIN shifts command-and-control resolution to Ethereum smart contracts
Technical Analysis UpdateKREMLIN moved its endpoint resolution and payload-hosting workflow to Ethereum smart contracts on May 19, 2026, using blockchain-based dead-drop resolvers to rotate C2 infrastructure and hide hosting locations.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 2 articles · 2h ago
Elastic Security Labs tracks REF9334 Brazilian banking malware operation
Initial DisclosureElastic Security Labs tracks REF9334 as a Brazilian banking malware operation that has been active since at least May 2025, uses lures impersonating Brazilian banks to install a malicious Chrome and Edge extension named "AVSync System Inc.", and steals credentials, session tokens, and sensitive data.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54