Back to all news
Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News·September 15, 2026·1 min read
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Elastic Security Labs uncovered a Brazilian banking malware operation delivering a toolkit called KREMLIN, active since at least May 2025. The threat actor impersonates a dozen Brazilian banks and installs a malicious browser extension on Chrome and Edge to steal credentials and session tokens, tracked as REF9334.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store