KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials

The Brazilian KREMLIN banking malware uses malicious Chrome and Edge extensions to steal credentials and session tokens, impersonating multiple Brazilian banks.

Why it matters

Targeting popular browsers increases the risk of credential theft from users of major Brazilian banks, threatening account security and financial operations.

SOC impact

Monitor browser activity for unauthorized extensions or suspicious behaviors related to credential and session token theft, specifically on Chrome and Edge. Review authentication logs for anomalies involving Brazilian banking applications. Investigate alerts linked to known KREMLIN tactics and signatures to assess exposure and potential compromise.

Recommended actions

  1. Identify and review all deployed Chrome and Edge extensions on user endpoints
  2. Monitor authentication logs for unusual access patterns to Brazilian banking services
  3. Investigate any alerts associated with KREMLIN malware indicators
  4. Assess endpoints for installation of unauthorized browser extensions
  5. Review session token usage and validity within affected banking applications

Executive Summary

Since May 2025, the KREMLIN banking malware has operated by deploying malicious extensions on Chrome and Edge browsers to steal credentials and session tokens from over a dozen Brazilian banks. This approach leverages the widespread use of these browsers to facilitate credential theft without direct system infection. The campaign’s impersonation of multiple financial institutions increases its potential impact, placing users and financial services at elevated risk of unauthorized access. Defenders must concentrate on detecting malicious browser extension activity and unauthorized session usage to mitigate this threat.

SOC Impact

Monitor browser activity for unauthorized extensions or suspicious behaviors related to credential and session token theft, specifically on Chrome and Edge. Review authentication logs for anomalies involving Brazilian banking applications. Investigate alerts linked to known KREMLIN tactics and signatures to assess exposure and potential compromise.

Browser and Credential Security Validation

  • Identify and review all deployed Chrome and Edge extensions on user endpoints
  • Monitor authentication logs for unusual access patterns to Brazilian banking services
  • Investigate any alerts associated with KREMLIN malware indicators
  • Assess endpoints for installation of unauthorized browser extensions
  • Review session token usage and validity within affected banking applications

Why It Matters

Targeting popular browsers increases the risk of credential theft from users of major Brazilian banks, threatening account security and financial operations.

Source