KREMLIN Toolkit Turns Chrome and Edge Into Brazilian Bank-Robbing Tools
Elastic Security Labs has pulled the lid off REF9334, a Brazilian crew pushing a rogue browser extension that impersonates a dozen local banks.

Key points
- Elastic Security Labs is tracking a Brazilian banking malware operation it calls REF9334, which uses a toolkit named KREMLIN.
- The campaign has been running since at least May 2025.
- Lures impersonate roughly a dozen Brazilian banks to trick victims into installing a malicious add-on for Google Chrome.
- The extension steals banking credentials and live session tokens straight from the browser.
Researchers have named a Brazilian banking operation that had been running quietly for months. Elastic Security Labs calls it REF9334, and the toolkit behind it KREMLIN. Activity dates to at least May 2025.
The attackers impersonate about a dozen Brazilian banks, steering victims into installing a booby-trapped browser extension, a small add-on that plugs into Chrome. Once it's in place, the browser itself becomes the thief.
That's the part worth pausing on. KREMLIN doesn't need to break Windows or slip past antivirus in the classic sense. It rides inside the browser the victim already trusts, watches them log in, and lifts what it sees.
What is KREMLIN actually doing?
KREMLIN installs a malicious browser extension to steal credentials and session tokens. Credentials are the username and password. A session token is the small digital pass a website hands your browser after you log in, so you don't have to retype your password on every click. Steal the token and you can walk straight into the account without the password at all.
A browser extension is a useful perch for criminals because it sits inside the page and can quietly read the same cookies the bank set for you. It's the same session-hijacking trick that has plagued webmail accounts for years. The novelty here is the packaging: a full named toolkit, aimed squarely at Brazilian retail banking, with lures tuned to local brands.
This also isn't Elastic's first appearance on our radar covering Latin American fraud. We reported on their REF6045 campaign targeting Mexican bank customers on 8 July, where a bogus CAPTCHA page tricked victims into running a malicious command instead.
Who is being targeted?
Customers of about a dozen Brazilian banks. Elastic hasn't published the full list, but the lures impersonate those brands to push people toward installing the extension. If you bank in Brazil and were prompted recently to add a browser add-on to "secure" or "verify" your account, treat that prompt as hostile.
The delivery pattern fits a long tradition. Latin American cybercrime crews have favoured banking trojans over ransomware for years, and a Brazilian crew we covered on 8 September targeting Pix instant payments showed the same regional instinct. KREMLIN moves that theft up into the browser layer, where modern banking authentication actually lives.
Should you worry?
Open Chrome or Edge, go to the extensions page, and look at what's installed. Remove anything you don't remember adding, anything claiming to be from your bank, and anything asking permission to read data on all sites you visit. Brazilian banks don't ship security tools through a Chrome Web Store add-on you found in an email.
If you think you installed something dodgy, change your online banking password from a clean device and call the bank to invalidate active sessions. That last step kills a stolen session token.
Rufus's read
The interesting thing about REF9334 isn't the malware. It's the target surface. Brazilian banks pushed hard into browser-based authentication, and the criminals followed the money into the browser. What I'd watch next is how quickly KREMLIN gets shared or sold between crews rather than staying with one group. The Latin American banking-malware scene has always been a fast follower of whatever the banks do next, and a packaged, branded toolkit is much easier to hand off than a bespoke trojan.



