securityonline.info 21 Sept 2026, 06:20 UTC

KREMLIN Malware Targets Brazilian Banks Through Chrome Extensions

KREMLIN Malware Targets Brazilian Banks Through Chrome Extensions

ELASTIC Security Labs has identified an active Brazilian campaign, tracked as REF9334, distributing the KREMLIN banking malware, also known as CHROMEBALLRAT. The campaign, reportedly active since May 2025, uses phishing emails containing JavaScript files disguised as invoices, bank statements, payment receipts and tax documents. The lures impersonate customers of 12 Brazilian financial institutions, including Banco do Brasil, Bradesco and Caixa.

The loader displays a fake document error while checking the system for signs of a sandbox, terminating if it finds fewer than 50 processes or five desktop files. Successful infections download Node.js, create a persistent scheduled task named MicrosoftNodeRuntimeUpdater, and use Ethereum smart contracts to obtain changing payload locations.

The malware deploys extensions into Google Chrome and Microsoft Edge profiles, modifying Secure Preferences and regenerating required HMACs and App-Bound encrypted hashes to bypass Chromium protections. It extracts encryption material from browser memory and files, then enables the extensions to steal cookies, session tokens and saved login databases. WebSocket connections provide remote control, while injected banking overlays can display fake QR codes and monitor login-form activity.

Elastic assesses the operators as probably Brazilian, citing Portuguese code comments, Brazilian bank lures and activity aligned with São Paulo working hours, but attribution is not confirmed.

Elastic registered a previously unregistered canary domain queried by the installer. This caused the malware to treat infected systems as analysis environments and stop, disrupting payloads on 1,515 systems; 98.75% were in Brazil. Recommended detection includes checking Chromium profiles for unauthorised extensions and altered preference files, auditing scheduled tasks, blocking script attachments and monitoring unusual blockchain RPC traffic.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline