Malware Hijacks Chrome and Edge: What You Need to Know About KREMLIN

·
Listen to this article~3 min
Malware Hijacks Chrome and Edge: What You Need to Know About KREMLIN

A new Brazilian banking malware, KREMLIN, hijacks Chrome and Edge to steal credentials and session tokens. Learn how to protect yourself and why antidetect browsers matter.

### A New Threat Emerges: KREMLIN Malware Cybersecurity researchers have uncovered a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. This malware is designed to steal credentials and session tokens by hijacking popular browsers like Google Chrome and Microsoft Edge. The threat actor, tracked as REF9334 by Elastic Security Labs, has been active since at least May 2025. They use lures that impersonate a dozen Brazilian banks to trick users into installing a malicious browser extension. ### How KREMLIN Operates Once installed, the malicious extension can capture login credentials and session tokens, giving attackers access to sensitive accounts. Session tokens are particularly dangerous because they allow attackers to bypass multi-factor authentication (MFA) and maintain persistent access. The malware targets both Chrome and Edge, two of the most widely used browsers in the world. ### Protecting Yourself from KREMLIN To protect yourself from this and similar threats, follow these best practices: - **Keep your browser updated:** Always install the latest security patches. - **Be cautious with extensions:** Only install extensions from official sources and check reviews. - **Use antidetect browsers for sensitive tasks:** Tools like antidetect browsers can help isolate your browsing sessions and prevent cross-contamination. - **Enable MFA:** While not foolproof, MFA adds an extra layer of security. - **Monitor accounts:** Regularly check for suspicious activity. ### The Rise of Antidetect Browsers As malware becomes more sophisticated, the need for robust privacy tools grows. Antidetect browsers are designed to mask your digital fingerprint, making it harder for attackers to track you across sessions. They're especially useful for professionals managing multiple online identities, such as e-commerce sellers, ad agencies, and security researchers. By using an antidetect browser, you can compartmentalize your activities and reduce the risk of credential theft. ### What's Next? Elastic Security Labs continues to monitor REF9334 and its activities. While the campaign currently targets Brazilian banks, such malware often spreads to other regions. Staying informed and adopting a multi-layered security approach is crucial. Remember, your digital security is only as strong as your weakest link—often, that's the browser you use every day. > "The KREMLIN malware is a wake-up call for anyone who thinks their browser is safe from credential theft. It's not just about antivirus anymore; it's about adopting a security-first mindset." – Robert Moore, Lead Antidetect Browser Specialist. Stay safe out there, and don't let your guard down.