KREMLIN (REF9334): Elastic documents Brazilian banking malware with Chromium integrity bypass + Ethereum C2
Elastic Security Labs (report dated 14 September 2026; The Hacker News 16 September IST) tracks REF9334 delivering the KREMLIN toolkit against Brazilian banking users since at least May 2025. Infection starts with a manually run JavaScript lure (banking/invoice/document themed), then a multi-stage loader with sandbox evasion, Node.js staging, scheduled-task persistence, and Ethereum smart-contract dead-drop resolvers for C2/payload URLs (domains cited include volmira[.]site and zaviro[.]online). A C++ installer sideloads via a SentinelOne-named binary (SentinelAgentCore.dll). Malicious Chrome/Edge extensions use Phantom Extension / GhostChrome-X style Secure Preferences HMAC/App-Bound hash forgery to steal credentials and session tokens. Elastic notes similarity of the integrity-bypass technique to APT31 BlueMoon/GemStone tradecraft but attributes this cluster to Brazilian banking focus. Primary: Elastic Security Labs; wire: The Hacker News.
- Product
- KREMLIN / REF9334 (Windows; Chrome/Edge malicious extensions; Ethereum dead-drop C2)
- Exploited in Australia?
- unknown
- Patch to
- Hunt unexpected Chromium Secure Preferences changes, SentinelOne-named sideloads, and Ethereum-resolved C2; block IoCs from Elastic report; user awareness on JS banking lures
Primary: Elastic Security Labs — KREMLIN / REF9334 browser-extension banking malware · Vendor: Elastic Security Labs Threat Command report · The Hacker News — KREMLIN banking malware (16 Sep 2026 IST)
