Summary
Elastic Security Labs has uncovered REF9334, a Brazilian banking malware campaign active since May 2025, which deploys malicious Chrome and Edge extensions named "Kremlin" to steal credentials and session tokens. The malware, primarily targeting Brazilian bank users, has infected over 1,500 systems and uses the Ethereum blockchain for C2 communication to evade detection.