Threat reportMalwareTL-2026-2525

KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials

highACTIVE

KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom (TL-2026-2525), also tracked as REF9334, is a high-severity malware campaign, first published 2026-09-15. It is attributed to REF9334 with medium confidence, affects Google Chrome, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1053), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
1REF9334
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-2525

Threat ID
TL-2026-2525
Also known as
REF9334
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
REF9334
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, banking
Target regions
brazil, Latin America
Detection rules
9
Indicators of compromise
29

Malware and tooling in KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom

Malware and tooling: DonutLoader, PULSAR, Pulsar RAT, REMCOS, cdgcjghdeinagopbaobhmaefigoafaaa, djodclnjknbpambeaaapadmdfhmbpeog, ndpbidppejfanjbhfgjlohfanbfbklff

How KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom works

Elastic Security Labs (tracked as REF9334) exposed KREMLIN, a Brazilian banking-malware toolkit active since May 2025 that impersonates about a dozen Brazilian banks to sideload a malicious Chrome/Edge extension using the publicly documented Phantom Extension/GhostChrome-X Secure Preferences integrity bypass. Later campaigns abuse a legitimate SentinelOne binary (SentinelMemoryScanner.exe) to DLL-sideload an unsigned payload (SentinelAgentCore.dll) and resolve C2 endpoints via an Ethereum smart contract acting as a dead-drop resolver. Elastic identified 1,515 infected systems (>98% in Brazil) via a disrupted network-canary domain.

KREMLIN is a Brazilian banking-malware ecosystem tracked by Elastic Security Labs under the moniker REF9334, active since at least May 2025 across seven distinct, evolving campaigns. Infection begins with a multi-stage obfuscated JavaScript loader (delivered as a fake banking/invoice document) that performs sandbox evasion (desktop file count, running process count, and a network canary check against an unregistered domain), decodes an embedded payload via certutil, and downloads a Node.js runtime. A second-stage loader installs persistence via a scheduled task (MicrosoftNodeRuntimeUpdater, triggered one minute after logon) and, in the newest campaign, queries an Ethereum smart contract (0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b) to resolve installer, sideload-carrier, and RunPE-carrier URLs, with payloads embedded as Base64/RC4-encoded data inside JPEG steganographic carriers (several hosted on Internet Archive).

A C++ installer (SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268) performs extensive sandbox/VM evasion (process, account, hardware, and VMware/VirtualBox artifact checks) and uses indirect syscalls (via the open-source PigSyscall technique, resolving NTDLL gadgets and API hashes) to evade EDR hooking. It then installs a malicious Chrome/Edge extension using the Phantom Extension/GhostChrome-X technique: it recovers the browser's App-Bound OSCrypt key via a debugger-attached LOAD_DLL_DEBUG_EVENT/pattern-scan of chrome.dll or msedge.dll, then rewrites the Secure Preferences file (enabling developer mode, injecting the malicious extension's settings, and forging protection.macs/*_encrypted_hash/super_mac HMAC integrity values) so Chrome accepts the unauthorized extension without triggering its tamper-detection. The extension (most recently ID ndpbidppejfanjbhfgjlohfanbfbklff, masquerading as "AVSync System Inc.") communicates over a WebSocket channel (/google_ws/) and an HTTP polling channel disguised as .css requests (/google_api/), and supports screenshot capture, tab/cookie/session/local-storage theft, browsing-history collection, full HTML injection, keylogging via input-event listeners, and domain-hash-matched HTTP request interception/redirection. Separately, the installer exfiltrates Login Data, Cookies, Web Data, and derived OSCrypt keys (keys.json) to volmira[.]site and zaviro[.]online, RC4-encrypted via the undocumented SystemFunction032 API.

In its seventh and current campaign (May 2026-present), KREMLIN operators abuse a legitimate SentinelOne binary, SentinelMemoryScanner.exe, to DLL-sideload an unsigned payload disguised as SentinelAgentCore.dll, and also deploy REMCOS RAT and PULSAR RAT alongside the extension. Financial analysis of the Ethereum smart contract's admin wallet (0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6) shows $20,778.97 USDT in / $19,016.96 USDT out across 149 transactions between June 2025 and August 2026, with transaction timing clustering around São Paulo working hours (UTC-3). Portuguese-language code artifacts, lure filenames, mutex names, and the toolkit author handle Kr3mlin4rt1st (first appearing in loader v1.33, February 2026) indicate a Brazil-based, financially motivated criminal operation -- the "KREMLIN" branding is not evidence of Russian state involvement. Elastic Threat Command disrupted over 1,500 active infections by registering the malware's unregistered sandbox-canary domain (creamp1eonlyfans[.]net).

MITRE ATT&CK techniques used in TL-2026-2525

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow

Persistence

T1053 Scheduled Task/Job; T1176 Software Extensions

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1566 Phishing

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom

  • Google — Chrome
    Vulnerable versions: All Chromium-based releases relying on Secure Preferences/protection.macs integrity, including >=144 with resources.pak-seeded hashing
  • Microsoft — Edge
    Vulnerable versions: Chromium-based Microsoft Edge
  • SentinelOne — SentinelMemoryScanner.exe (Sentinel Agent component)
    Vulnerable versions: Abused as an unsigned-DLL sideloading host for SentinelAgentCore.dll

Remediation for KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom

Immediate actions

  • Block and hunt for the identified KREMLIN C2 domains/IPs at DNS and perimeter layers (volmira.site, zaviro.online, luizestrelhashapr.online, lojinhadoluiz.online, cremeb.com, granderevolucao.store, seguranca.versionnova.site, 178.92.162.38, 37.16.74.100, 37.16.74.34, 144.172.112.239, 45.90.13.210, 185.221.23.133)
  • Force-remove and blocklist the malicious extension IDs via enterprise Chrome/Edge management (ndpbidppejfanjbhfgjlohfanbfbklff, djodclnjknbpambeaaapadmdfhmbpeog, cdgcjghdeinagopbaobhmaefigoafaaa)
  • Audit endpoints for an unsigned SentinelAgentCore.dll co-located with or loaded by SentinelMemoryScanner.exe outside the expected SentinelOne installation directory
  • Hunt for the scheduled task 'MicrosoftNodeRuntimeUpdater' and unexpected 'conhost.exe --headless node.exe' process chains

Workarounds

  • Disable Chrome/Edge developer mode via enterprise policy (ExtensionDeveloperModeSettings) to close the Secure Preferences tampering surface
  • Restrict execution of SentinelMemoryScanner.exe via application control to its signed installation path only

Longer-term hardening

  • Deploy EDR with behavioral detection for process hollowing (RunPE) and indirect/hashed syscall usage (PigSyscall-style NTDLL gadget resolution)
  • Enforce browser management policy (ExtensionInstallBlocklist, disabled developer mode) to prevent Secure Preferences tampering and unauthorized extension sideloading
  • Monitor for debugger attachment to browser processes and LOAD_DLL_DEBUG_EVENT-based App-Bound key extraction as a credential-theft precursor
  • Add outbound monitoring for anomalous Ethereum JSON-RPC/Web3 calls from endpoint processes as a dead-drop-resolver C2 indicator

Timeline of KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom

  • Earliest RunPE-module JPEG steganographic carrier (output_image_202505.jpg) uploaded to Internet Archive by uploader account 'Radduxx'.
  • Campaign 1 ('Codecaudiog A') begins: PowerShell to RunPE to Installer chain delivering the malicious extension, DonutLoader, and PULSAR 1.6.6/1.7.3, C2 at 185.221.23.133.
  • Financial activity begins on the Ethereum admin wallet (0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6) that later funds and controls the KREMLIN C2 smart contract.
  • Campaign 3 ('Acrobat') begins: Adobe-plugin lure delivering PULSAR 1.7.1/1.7.2 only (no extension) via JavaScript to PowerShell to RunPE to DonutLoader chain.
  • Campaign 4 ('Framesync') begins: FrameSync-branded extension (ID djodclnjknbpambeaaapadmdfhmbpeog) with dynamic C2 resolution via an abused Cloudflare Workers endpoint.
  • Campaign 5 ('Donalurdesconfeitos to Cremeb') begins, migrating infrastructure across donalurdesconfeitos.site, marialurdes.site, harialurdes.site, and cremeb.com through March 2026.
  • First 'KREMLIN' branding (version 1.33) appears in the JSE-encoded loader, attributed to toolkit author 'Kr3mlin4rt1st'.
  • Campaign 6 ('Cremeb') begins: QR-code-themed extension (ID cdgcjghdeinagopbaobhmaefigoafaaa) targeting web.whatsapp.com and sicoob.com.br, delivering PULSAR 2.4.5 via Early Cascade Injection into explorer.exe.
  • KREMLIN operators deploy their first Ethereum smart contract (0x902Edb...) as a C2/payload dead-drop resolver.
  • Rubrik Zero Labs publicly discloses the GhostChrome-X Chrome extension integrity-bypass technique later leveraged by KREMLIN's Phantom Extension installer.
  • Campaign 7 ('Ethereum Transition') begins: current smart contract 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b deployed with main-v2/sentinel/sub-module config variables; SentinelMemoryScanner.exe DLL-sideloading installer variant and REMCOS RAT introduced.
  • Last transaction recorded in Elastic's observed window on the KREMLIN C2 smart contract's admin wallet ($20,778.97 USDT in / $19,016.96 USDT out across the tracked period).
  • Elastic Security Labs publishes REF9334/KREMLIN research; The Hacker News reports 1,515 infected systems (>98% in Brazil) identified after Elastic Threat Command registered the malware's sandbox-canary domain to disrupt infections.

Sources cited for KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom

Detection coverage for TL-2026-2525

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2525 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats