Cybersecurity

New Brazilian Banking Malware Campaign Deploys KREMLIN Toolkit via Blockchain-Infused Infrastructure

Cybersecurity researchers have uncovered a sophisticated and highly resilient banking malware operation targeting financial institutions across Brazil. Tracked by Elastic Security Labs under the designation REF9334, the campaign centers on a malicious toolkit known as KREMLIN. Since its emergence in May 2025, this threat actor has demonstrated a high degree of technical ingenuity, particularly in its use of decentralized blockchain technology to obscure command-and-control (C2) infrastructure and its advanced methods for bypassing browser security protocols.

The operation primarily targets users of Google Chrome and Microsoft Edge, coercing victims into installing a malicious browser extension that functions as a persistent surveillance and credential-harvesting tool. By masquerading as legitimate banking, invoice, or corporate documentation, the threat actors successfully distribute the initial JavaScript-based loader, which initiates a complex, multi-stage infection process designed to evade both automated sandbox analysis and human scrutiny.

The Anatomy of the KREMLIN Infection Chain

The lifecycle of a KREMLIN infection is characterized by its modularity and strict adherence to environmental conditions. The initial vector, a deceptively named JavaScript file, requires manual execution by the victim. Once triggered, the malware performs a series of "canary" checks to determine if it is being executed within a virtual machine or a sandbox environment—security measures commonly used by researchers to analyze malicious code.

If the environment is deemed safe, the loader proceeds to the second stage. This phase is critical for the long-term viability of the attack; it establishes persistence on the host system via a scheduled task. Crucially, it initiates communication with an Ethereum smart contract. This innovative approach acts as a "dead drop resolver," allowing the attackers to dynamically update the locations of their C2 servers and secondary payloads without relying on static domains that are easily identified and sinkholed by security vendors.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The third stage involves the deployment of a custom C++ installer. This binary employs a "side-loading" technique, abusing a legitimate SentinelOne binary to execute an unsigned payload disguised as "SentinelAgentCore.dll." This DLL further enforces the malware’s security checks, terminating execution if it detects specific hardware configurations—such as limited CPU counts or low RAM—often associated with sandbox analysis environments.

The Role of Blockchain in Infrastructure Resilience

The integration of Ethereum smart contracts into the malware’s C2 architecture represents a significant evolution in the tactics of Brazilian threat actors. By leveraging the blockchain, the operators of REF9334 have effectively decentralized their infrastructure. Even if security researchers identify and block specific IP addresses or domain names, the malware can simply query the smart contract to retrieve updated, active infrastructure locations.

This "decentralized C2" model is notoriously difficult to disrupt. Traditional takedown operations require working with domain registrars or hosting providers to seize infrastructure. However, because the smart contract itself is immutable and exists on the Ethereum ledger, it cannot be easily taken offline. This provides the KREMLIN operators with a persistent, highly agile communication channel that has allowed them to maintain their operations since May 2025 across at least seven distinct campaigns.

Sophisticated Browser Hijacking Techniques

A hallmark of the KREMLIN operation is its ability to bypass Chromium’s integrity protections to install a malicious extension, which researchers identify as "AVSync System Inc." The malware achieves this by manipulating the browser’s "Secure Preferences" file. It manually regenerates required HMACs (Hash-based Message Authentication Codes) and App-Bound encrypted hashes, effectively tricking the browser into accepting the malicious extension as a legitimate, user-installed component.

This technique, which echoes methodologies used in the "Phantom Extension" and "GhostChrome-X" exploits, allows the malware to gain elevated privileges within the browser environment. Once installed, the extension requests broad permissions, including access to cookies, session tokens, and the webRequest API. This capability grants the attackers the ability to intercept banking credentials, bypass two-factor authentication (2FA) by stealing session cookies, and monitor sensitive user data in real-time.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Chronology of Operations and Development

The timeline of REF9334 activity reveals a consistent, iterative development process:

  • May 2025: Initial emergence of the REF9334 actor group and the commencement of campaigns targeting Brazilian financial institutions.
  • June 16, 2025: The start of the first of seven identified, major, and distinct attack campaigns.
  • May 19, 2026: A pivotal transition in the group’s operational security, as the actors began integrating Ethereum smart contracts to manage their C2 infrastructure.
  • August 2026: Observation of similar integrity-bypass techniques being utilized by other, potentially state-sponsored actors, such as the China-linked APT31, indicating a convergence of sophisticated techniques within the broader cyber-criminal landscape.

Throughout this period, the group has utilized various off-the-shelf malware, including the Pulsar RAT and Remcos RAT, alongside their proprietary KREMLIN toolkit. This hybrid approach allows the attackers to maintain a versatile arsenal capable of both broad-spectrum data collection and targeted financial theft.

Analysis of the Threat Landscape

The emergence of KREMLIN underscores a growing trend of professionalization within Brazilian cybercrime. By combining traditional social engineering—such as the distribution of fake invoices—with advanced persistence mechanisms and blockchain-based C2, the REF9334 group has created a formidable threat.

Elastic Security Labs noted that their intervention, which involved registering one of the malware’s "network canary" domains, successfully exposed the scale of the infection. By monitoring the check-ins from infected systems, researchers identified 1,515 unique compromised hosts. The fact that 98% of these systems are located in Brazil confirms the highly targeted nature of the campaign, which focuses on local banking ecosystems and native language lures.

While the intervention has provided security defenders with a temporary advantage and a window for remediation, the resilience of the Ethereum-based infrastructure means that the threat remains active. The ability of the malware to "call home" and potentially update its malicious code poses an ongoing risk to both individual consumers and corporate entities in the region.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Implications for Financial Cybersecurity

The KREMLIN campaign presents several challenges for financial institutions and cybersecurity professionals:

  1. Detection Difficulty: Because the malware utilizes legitimate software binaries (such as SentinelOne) to hide its activities and employs blockchain for C2, standard signature-based detection methods are often ineffective.
  2. Browser Security Gaps: The success of the "Phantom Extension" technique highlights persistent vulnerabilities in how browsers verify the integrity of extensions. As browsers become the primary interface for banking, the threat to browser-based security will likely escalate.
  3. Data Exfiltration Risks: The ability of the KREMLIN extension to steal session tokens is particularly concerning. Even if a user utilizes strong passwords, the theft of session data allows attackers to hijack active banking sessions, rendering traditional login security measures moot.

Mitigations and Recommendations

Security experts recommend that both individuals and organizations adopt a multi-layered defense strategy. For organizations, implementing rigorous endpoint detection and response (EDR) solutions that can identify the subtle behavioral anomalies—such as the unauthorized modification of browser preferences or the execution of unsigned DLLs—is essential.

Furthermore, users should be educated on the dangers of manually executing files received through unsolicited communications. The reliance on human intervention to trigger the initial loader remains the "weakest link" in the infection chain. Regular audits of installed browser extensions and the implementation of Group Policy Objects (GPOs) to restrict the installation of unauthorized extensions in corporate environments can significantly reduce the risk of a KREMLIN-style breach.

As the REF9334 group continues to iterate on its KREMLIN toolkit, the security community must remain vigilant. The integration of decentralized ledger technology into malware infrastructure marks a new chapter in the ongoing arms race between cyber-adversaries and those tasked with defending the global financial system. The persistence and ingenuity of this campaign serve as a stark reminder of the evolving capabilities of modern threat actors.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Jar Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.