Lotu Radar About · RSS

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News Cybersecurity Score 8/10

Summary

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

SecurityThreat Intel

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.