KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Summary
Brazilian banking malware, dubbed KREMLIN, has been identified by researchers and is actively targeting users since at least May 2025. The malware operates by installing a malicious browser extension on Google Chrome and Edge to steal user credentials and session tokens.
IFF Assessment
The KREMLIN malware actively steals sensitive banking credentials and session tokens, posing a direct threat to users and financial institutions.
Defender Context
This operation highlights the ongoing threat of banking trojans that leverage social engineering and browser extensions to compromise user accounts. Defenders should remain vigilant against phishing attempts that impersonate financial institutions and educate users about the risks of installing browser extensions from untrusted sources.