Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [incident, financial-services] ยท confidence: high ยท severity: low ยท affected_sectors: [financial-services] ยท au_impact: true

Elastic Security Labs has published a full account of the operation it tracks as REF9334, a Brazilian banking-malware ecosystem whose toolkit the malware author names KREMLIN โ€” an artefact of the author's handle, Kr3mlin4rt1st, rather than any Russian nexus: the lures impersonate twelve Brazilian banks, the error messages and code comments are in Portuguese, and the operators' Ethereum transactions cluster during Sรฃo Paulo working hours. Elastic has followed the group since May 2025 and documents seven campaigns across fifteen months. The infection chain begins with a JavaScript file masquerading as a bank receipt, invoice or company document that the user executes manually; the loader checks for sandbox and virtual-machine indicators, then pulls staged binaries from multiple hosts. The notable engineering is in the payload: a malicious browser extension that installs itself into Chrome and Edge and which the browser subsequently loads as though the user had approved it. It achieves that by manipulating Chromium's Secure Preferences store and regenerating the required HMACs and App-Bound encrypted hashes, so the browser's own tamper-detection logic is satisfied by forged values. Command-and-control resolution is handled through Ethereum smart contracts used as dead-drop resolvers, letting the operators rotate C2 endpoints and payload hosting without touching the malware. The operation's objective is banking sessions โ€” credentials, session tokens and sensitive data โ€” and Elastic assesses the primary focus as Brazilian banking users and financial institutions. Elastic's Threat Command team also disrupted the campaign at the infrastructure layer, registering the network canary โ€” kill-switch โ€” domain and disrupting more than 1,500 infections in the reported campaign, which is still counting. The transferable lesson for defenders is not the banking angle: it is that a browser's integrity-checked extension store is a defence that can be forged offline by an attacker who understands the format, so endpoint detection of unexpected extension loads matters more than trust in the store's tamper protection.

Attribute Detail
Sector Financial Services
Date 2026-09-16
Source Elastic Security Labs
Reliability Tier 1