Essential Insights
- The KREMLIN malware employs multi-stage loaders, malicious browser extensions, and blockchain-based C2 infrastructure to evade detection and dynamically update attack endpoints.
- Attackers leverage Chrome and Edge extension exploits, bypassing security protections using Phantom Extension techniques, to exfiltrate browser data and control infected systems remotely.
- The operation targets Brazilian financial institutions, stealing credentials, session tokens, and browser data through sophisticated evasion and persistence methods, impacting banking security.
The Threat, Attack Techniques, and Targets
Cybersecurity researchers uncovered a new Brazilian banking malware operation called KREMLIN. This malware has been active since at least May 2025. The attacker uses fake emails pretending to be bank documents or invoices. When victims open these emails, they execute a JavaScript file. This file then runs a complex, multi-stage loader that downloads more malicious payloads. These payloads include a spy browser extension and other tools.
The malware targets people who use Google Chrome or Microsoft Edge. It focuses on stealing IDs and session tokens from Brazilian banking users. The malware installs malicious browser extensions that impersonate legitimate ones. These extensions bypass security protections by changing internal files and encryptions. The attacker uses Ethereum smart contracts to hide their server addresses and update commands dynamically. This makes it hard to detect and shut down the operation.
The malware has several steps. First, it downloads the main JavaScript. Then, it installs itself on the victim’s system after evading sandbox tests. It also checks other running software and hardware details before fully activating. Once installed, the extension can access browser data and control commands sent from the attacker.
Impact, Security Implications, and Remediation Guidance
KREMLIN can steal sensitive banking data, credentials, and session tokens. It also exfiltrates browser data, cookies, and history. Its ability to bypass security defenses makes it difficult to stop once installed. The malware can take screenshots, steal internal browser data, and execute commands remotely. This poses a serious risk for banking users and organizations by enabling financial theft and identity fraud.
The malware’s use of blockchain and smart contracts helps it remain active and hidden longer. Detection can be challenging due to the circumvention of security protections and the use of legitimate systems like SentinelOne. The malware also performs evasive checks to avoid sandbox and virtual machine environments, which makes analysis harder.
While specific remediation guidance was not provided, defenders should obtain advice from the relevant vendors or authorities. Proper endpoint detection and response measures, regular patching, and monitoring browser extensions are strongly recommended. Blocking malicious extensions and verifying the integrity of browser settings can reduce risk. Continuous network monitoring and threat hunting can help identify unusual activity related to this malware.
Continue Your Tech Journey
Explore the future of technology with our detailed insights on Artificial Intelligence.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
