Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

KREMLIN Banking Malware Leverages Blockchain Infrastructure to Target Financial Institutions Across Brazil

Cahyo Dewo, September 16, 2026

Cybersecurity researchers at Elastic Security Labs have uncovered a sophisticated and highly resilient banking malware campaign, identified as REF9334, which has been systematically targeting Brazilian financial institutions since May 2025. The operation revolves around a modular toolkit dubbed KREMLIN, which utilizes unconventional methods—including the integration of blockchain technology—to maintain persistence and evade detection by security software. By masquerading as legitimate banking documents and invoices, the threat actors have successfully compromised thousands of systems, primarily focusing their efforts on the Brazilian banking sector.

The KREMLIN ecosystem is notable for its multi-stage architecture. The infection chain begins with a deceptively simple JavaScript file, which is manually executed by victims who have been lured by social engineering tactics. Once triggered, this initial stage conducts a series of environmental checks designed to determine if the malware is operating within a secure sandbox or a virtual machine environment—a common tactic used by security researchers to analyze malicious code. If the environment is deemed "clean" and suitable for infection, the loader proceeds to download subsequent payloads, effectively building a persistent foothold on the host machine.

Chronology of the REF9334 Campaign

The emergence of the REF9334 group represents a significant evolution in the landscape of regional banking threats. Since its inception, the group has demonstrated a high degree of adaptability, refining its techniques over at least seven distinct campaigns documented since June 16, 2025.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
  • May 2025: Initial activity of the threat actor group is first observed, involving the distribution of off-the-shelf remote access trojans (RATs) such as Pulsar RAT and Remcos RAT.
  • May 19, 2026: A pivotal shift in operational security occurs as the group integrates Ethereum smart contracts into their infrastructure. This move allows the threat actors to use the blockchain as a decentralized "dead drop" resolver, dynamically updating their command-and-control (C2) server locations in real-time.
  • August 2026: The group’s technical sophistication reaches a new high, mirroring tactics seen in other high-level state-sponsored operations, specifically regarding the exploitation of browser integrity mechanisms.
  • Late 2026 – Present: The campaign continues to expand, with researchers identifying over 1,515 unique infected endpoints, with a overwhelming 98% concentration within Brazilian territory.

Technical Sophistication and Infrastructure Obfuscation

The core of the KREMLIN toolkit’s effectiveness lies in its ability to bypass standard browser security. Once the initial loader establishes a foothold, it deploys a custom C++ installer that employs binary sideloading. By masquerading as a legitimate SentinelOne security component—specifically renaming itself to "SentinelAgentCore.dll"—the malware effectively hides in plain sight, leveraging the trust usually afforded to security software to bypass heuristic analysis.

Perhaps the most innovative aspect of this operation is the use of Ethereum smart contracts to manage C2 communication. By hosting the infrastructure’s configuration on the blockchain, the threat actors ensure that their C2 endpoints are not tethered to a single domain or IP address that could be easily seized or blacklisted by internet service providers or law enforcement. When a machine is infected, it queries a specific Ethereum address to retrieve the latest hosting locations for the next stage of the payload. This decentralized approach makes the infrastructure incredibly resilient, as disrupting the malware requires more than simply taking down a traditional web server.

Bypassing Chromium Integrity Protections

Once the C++ stage is complete, the malware focuses on its primary objective: the deployment of a malicious browser extension, identified by the researchers as "AVSync System Inc." This extension is specifically designed to compromise Google Chrome and Microsoft Edge, the most widely used browsers in the region.

The installation process is particularly aggressive, utilizing a technique known as "Phantom Extension" hijacking. By manipulating the browser’s "Secure Preferences" file and regenerating the required Hash-based Message Authentication Codes (HMACs) and App-Bound encrypted hashes, the malware forces the browser to accept the malicious extension as a legitimate, user-installed component. This effectively bypasses the built-in integrity mechanisms that usually prevent unauthorized software from modifying browser settings.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The extension itself is equipped with extensive permissions, granting the attackers the ability to monitor web traffic, intercept session tokens, and steal login credentials in real-time. By interacting with the browser’s webRequest API and monitoring tab activity, the malware can specifically target the banking portals of a dozen major Brazilian institutions, waiting for the user to authenticate before harvesting sensitive financial data.

Defensive Analysis and Network Canary Mechanisms

As part of their investigation, Elastic Security Labs discovered a "network canary" mechanism embedded within the KREMLIN code. The malware attempts to reach an unregistered domain to verify the environment; if it receives a successful response, it assumes the system is being monitored or is within a sandboxed environment, causing the malware to crash intentionally to prevent further analysis.

Elastic researchers successfully registered this canary domain, providing them with a unique window into the scale of the infection. By monitoring the traffic attempting to "check in" with the canary domain, they were able to identify over 1,500 infected systems. While this discovery provided crucial data for the security community, it also served to degrade the malware’s own defensive capabilities. By forcing the malware to receive a "successful" response from the canary domain, researchers were able to manipulate the group’s internal logic, providing a temporary window for remediation and mitigation across the affected systems.

Broader Implications for the Financial Sector

The activities of REF9334 underscore a growing trend in the cyber-threat landscape: the professionalization of regional banking malware. No longer limited to basic credential stealing, these groups are now employing advanced techniques previously reserved for state-sponsored Advanced Persistent Threats (APTs). The use of blockchain infrastructure, combined with the exploitation of zero-day or N-day browser vulnerabilities, indicates that the developers behind KREMLIN possess a high level of technical expertise and significant resources.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

For the banking sector, the implications are profound. The ability of the KREMLIN toolkit to intercept session tokens means that even multi-factor authentication (MFA) can be bypassed if the session is already active or if the malware can capture the session cookie. Financial institutions must move beyond traditional perimeter defenses and adopt a more robust, endpoint-centric approach to security. This includes rigorous monitoring of browser integrity, the implementation of behavioral analysis for browser extensions, and the adoption of more advanced threat intelligence feeds that can track the evolving infrastructure of such groups.

The success of the KREMLIN operation in Brazil serves as a warning for financial sectors globally. As threat actors continue to integrate decentralized technologies like blockchain to obfuscate their activities, the traditional "cat-and-mouse" game between security researchers and cybercriminals is entering a more complex phase. Organizations are advised to audit their environments for the specific indicators of compromise associated with REF9334 and to ensure that endpoint protection solutions are updated to detect the "SentinelAgentCore.dll" anomaly and unauthorized modifications to Chromium-based Secure Preferences.

As the investigation into KREMLIN continues, the cybersecurity community remains focused on dismantling the infrastructure that supports these campaigns. The shift toward blockchain-based C2 resolution marks a significant hurdle for traditional takedown efforts, necessitating a global, collaborative approach to tracking these malicious smart contracts and preventing the further exploitation of financial users.

Cybersecurity & Digital Privacy acrossbankingBlockchainbrazilCybercrimefinancialHackingInfrastructureinstitutionskremlinleveragesmalwarePrivacySecuritytarget

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes