# Researchers detail KREMLIN banking-malware operation in Brazil

_Published Tuesday, September 15, 2026 at 5:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Researchers detail KREMLIN banking-malware operation in Brazil — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPTs6qupSdjinGg233zkoldOvlD4cva51loWufV3l9GrlDopNRIKsV9yluCDjbGELBAAvVGx_h4R-sjx4jvDp290Znzhv6j546sq5JB0NJUShGVV3w0gKU7nu4dBVCosaPeKW-Pr1_WHn4FV26aEJRgEo7oSJsgUE5_ZGCMKWPPBdZ7NMh5XRr04Cs6qTh/s1700-nu-rw-lo-l85-e365/browser-malware.jpg)

Elastic Security Labs reported a Brazilian banking-malware operation it calls REF9334, which delivers the KREMLIN toolkit through lures impersonating Brazilian banks. Researchers said the malware installs malicious Chrome and Edge extensions to steal credentials, session tokens and other browser data. The operation uses Ethereum smart contracts to update command-and-control endpoints and payload locations. Elastic said it identified 1,515 infected systems checking a registered canary domain, with more than 98% geolocated in Brazil.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)

---
Canonical: https://techandbusiness.org/newswire/AQemzkFPuaYUDyuVKj4bcK
Published: 2026-09-15T21:07:26.261Z
Story chronology: 2026-09-15T18:54:14.000Z
Retrieved: 2026-09-15T23:11:56.605Z
Publisher: Tech & Business (techandbusiness.org)
