New Undocumented Brazilian Banking Malware Operation ‘KREMLIN’ Uncovered By Security Researchers

Cybersecurity analysts have uncovered a sophisticated and previously undocumented financial malware operation targeting South America, specifically focusing on institutions and account holders in Brazil. Tracked under the threat cluster designation REF9334 by Elastic Security Labs, the campaign deploys a formidable toolset dubbed KREMLIN. Active since at least May 2025, the threat group has demonstrated advanced technical capabilities, leveraging blockchain technology to conceal its command-and-control (C2) infrastructure while deploying malicious browser extensions to compromise Google Chrome and Microsoft Edge on targeted systems.
The emergence of the KREMLIN malware ecosystem underscores a troubling evolution in cybercrime methodologies originating within the region. Historically, Latin American banking trojans relied heavily on screen-locking overlays, VNC-based session hijacking, and direct keystroke logging. However, the operators behind REF9334 have integrated modern web browser manipulation, cryptographic evasion techniques, and decentralized network architecture into their attack chains. This shift allows the malicious toolset to bypass standard endpoint protections and Chromium security architectures, placing sensitive financial data, authentication tokens, and corporate credentials at severe risk.
Anatomy of the Attack: Multi-Stage Infection Vectors
The deployment of KREMLIN begins with social engineering lures designed to mimic official Brazilian financial communications, corporate invoicing documents, or government notices. These initial vectors typically arrive via phishing emails or compromised web portals hosting malicious JavaScript files. When a targeted user manually executes the file, the infection chain initiates a series of rigorous environmental checks designed to frustrate automated analysis and security research.
Before proceeding with payload delivery, the multi-stage loader checks whether it is operating within a sandbox or a virtual machine. It cross-references active system processes against a hard-coded blacklist of known analysis tools, hypervisors, and security environments. Furthermore, the malware assesses fundamental hardware properties, requiring specific system resources—such as a minimum of two CPU cores and more than 3 gigabytes of RAM—to ensure it is running on a genuine victim workstation. If the environment appears to be an analytical sandbox or an underspecced machine, the process terminates immediately to protect the operation’s operational security.

Once the initial checks are successfully passed, the malware establishes persistence through scheduled tasks and prepares for the execution of subsequent stages. A notable characteristic of the second stage is its reliance on decentralized infrastructure. Rather than querying traditional, easily blockable domain name servers or hard-coded IP addresses for C2 instructions, the malware communicates directly with an Ethereum smart contract operating on the public blockchain. By utilizing Ethereum smart contracts as dead drop resolvers, the threat actors can dynamically update C2 endpoints and payload hosting locations in real time without modifying the underlying binary code.
Exploiting Chromium Integrity: The Phantom Extension Technique
A core component of the KREMLIN toolkit involves the installation of a malicious browser extension disguised as a legitimate enterprise tool named "AVSync System Inc." (associated with extension ID ndpbidppejfanjbhfgjlohfanbfbklff). To distribute and install this extension across Chromium-based browsers like Google Chrome and Microsoft Edge without alerting the user or triggering native browser protections, the threat actors leverage advanced integrity bypass techniques commonly referred to in the security community as "Phantom Extension" or "GhostChrome-X."
Chromium-based browsers employ robust security mechanisms, including Secure Preferences and cryptographic message authentication codes (MACs), to prevent unauthorized modifications or the silent installation of unverified extensions. The KREMLIN C++ installer—which often masquerades as a legitimate security component by abusing the SentinelOne binary structure to sideload an unsigned payload named "SentinelAgentCore.dll"—actively circumvents these safeguards.
The payload modifies the browser’s Secure Preferences file, forcibly enables developer mode, and recalculates required HMACs and App-Bound encrypted hashes to forge valid metadata. This sophisticated manipulation tricks the browser into accepting the malicious extension as a trusted, locally managed component. Consequently, the extension is silently installed without displaying standard warning prompts or requiring manual user confirmation.
Once integrated into the browser environment, the extension requests expansive permissions, including deep access to active browser tabs, cookies, local storage, and the webRequest API. It generates a unique victim identifier that is stored locally and transmitted during subsequent communications. The extension maintains persistent connectivity through a WebSocket channel established with a primary C2 server (luizestrelhashapr[.]online:443), while also periodically polling a secondary "/google_api/" endpoint using requests disguised as benign CSS file fetches to receive operational commands.

Chronology and Evolution of Threat Cluster REF9334
The historical timeline compiled by security researchers highlights a calculated progression in the capabilities and infrastructure of the REF9334 threat group. Activity linked to this cluster spans multiple distinct campaigns dating back to mid-2025:
- May 2025: Initial indicators of the threat actor’s operational presence emerge, marked by the distribution of off-the-shelf remote access trojans (RATs) such as Pulsar RAT and fileless Remcos RAT alongside early iterations of malicious browser extensions.
- June 16, 2025 to Early 2026: The group executes a series of distinct campaigns focusing on impersonating prominent Brazilian banking institutions, refining their social engineering lures, and testing sandbox-evade mechanisms.
- May 19, 2026: A critical technological pivot occurs as the operators transition their infrastructure management strategy to incorporate Ethereum smart contracts as decentralized dead drop resolvers.
- Late August 2026: Parallels emerge between the techniques employed by KREMLIN and other advanced threat actors, such as the China-linked APT31 group utilizing similar Phantom Extension methodologies and exploit kits to deploy credential-stealing extensions like GemStone.
- Current Operations: The deployment of the full KREMLIN multi-stage ecosystem continues to target financial institutions and corporate networks predominantly within Brazil, utilizing advanced C++ installers and blockchain-backed infrastructure updates.
Network Canary Disruption and Victim Demographics
A fascinating development in the investigation of the KREMLIN operation involved the analysis of the malware’s built-in network canary mechanism. As part of its extensive anti-analysis routine, the malware attempts to download a specific page from an unregistered, threat-actor-controlled domain. If the connection yields a valid response, the malware assumes it is running within an isolated or simulated sandbox environment that improperly responds to arbitrary domain queries, prompting the malware to intentionally crash itself to avoid exposure.
Security researchers at Elastic seized the initiative by registering the network canary domain themselves. By controlling this endpoint, researchers gained unprecedented visibility into the geographical distribution and scale of the infection base. Telemetry data collected from the canary domain revealed that 1,515 infected systems attempted to check into the network.
The data confirmed a heavily localized targeting strategy: more than 98% of the identified victim systems are geolocated directly within Brazil. While these compromised endpoints still harbor the underlying payloads of the KREMLIN toolkit, the intervention effectively disrupted and manipulated the campaign’s native defense mechanisms. Security analysts note that this temporary degradation buys critical time for enterprise defenders and incident responders to identify, isolate, and remediate infected machines before financial losses can be realized.
Broader Implications and Enterprise Defense Strategies
The integration of blockchain-based infrastructure management and advanced Chromium integrity bypasses highlights an ongoing trend: cybercriminals are adopting sophisticated tactics historically associated with nation-state Advanced Persistent Threat (APT) groups. The use of decentralized smart contracts for C2 resolution presents significant challenges for traditional law enforcement takedowns and perimeter defense filtering, as decentralized ledgers cannot be easily seized or disabled through standard domain-name confiscation.

Furthermore, the abuse of browser extensions as primary persistence and credential-harvesting mechanisms demonstrates the shifting attack surface away from traditional operating system files and toward web-centric workflows. With modern enterprise users conducting the vast majority of their daily operations within web browsers—accessing corporate SaaS platforms, cloud storage, and online banking portals—compromised browsers offer cybercriminals direct visibility into authenticated sessions, bypassing multi-factor authentication (MFA) tokens that rely on session cookie validity.
Cybersecurity authorities and enterprise security teams recommend several proactive measures to mitigate the risks posed by campaigns like KREMLIN:
- Endpoint Protection Enhancement: Deploy modern Endpoint Detection and Response (EDR) solutions capable of monitoring unauthorized modifications to browser profile directories, Secure Preferences files, and cryptographic hash objects.
- Browser Policy Enforcement: Utilize centralized enterprise management policies to restrict the unauthorized installation of browser extensions, disable developer mode capabilities on standard workstations, and mandate corporate-approved extension whitelists.
- Blockchain Traffic Monitoring: Incorporate threat intelligence feeds that monitor anomalous interactions with known malicious or suspicious smart contract addresses associated with cybercriminal infrastructure.
- User Awareness Training: Conduct targeted phishing simulations focusing on financial document lures and invoice scams to reduce the likelihood of manual script execution by end users.
As threat actors continue to innovate their delivery mechanisms and leverage decentralized technologies, cybersecurity researchers emphasize the necessity of cross-industry collaboration, rapid intelligence sharing, and behavioral-based detection methodologies to disrupt evolving financial cybercrime operations globally.







