Threat reportMalwareTL-2026-2525
KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials
KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom (TL-2026-2525), also tracked as REF9334, is a high-severity malware campaign, first published 2026-09-15. It is attributed to REF9334 with medium confidence, affects Google Chrome, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1053), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1REF9334
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-2525
- Threat ID
- TL-2026-2525
- Also known as
- REF9334
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- REF9334
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking
- Target regions
- brazil, Latin America
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom
Malware and tooling: DonutLoader, PULSAR, Pulsar RAT, REMCOS, cdgcjghdeinagopbaobhmaefigoafaaa, djodclnjknbpambeaaapadmdfhmbpeog, ndpbidppejfanjbhfgjlohfanbfbklff
How KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom works
Elastic Security Labs (tracked as REF9334) exposed KREMLIN, a Brazilian banking-malware toolkit active since May 2025 that impersonates about a dozen Brazilian banks to sideload a malicious Chrome/Edge extension using the publicly documented Phantom Extension/GhostChrome-X Secure Preferences integrity bypass. Later campaigns abuse a legitimate SentinelOne binary (SentinelMemoryScanner.exe) to DLL-sideload an unsigned payload (SentinelAgentCore.dll) and resolve C2 endpoints via an Ethereum smart contract acting as a dead-drop resolver. Elastic identified 1,515 infected systems (>98% in Brazil) via a disrupted network-canary domain.
KREMLIN is a Brazilian banking-malware ecosystem tracked by Elastic Security Labs under the moniker REF9334, active since at least May 2025 across seven distinct, evolving campaigns. Infection begins with a multi-stage obfuscated JavaScript loader (delivered as a fake banking/invoice document) that performs sandbox evasion (desktop file count, running process count, and a network canary check against an unregistered domain), decodes an embedded payload via certutil, and downloads a Node.js runtime. A second-stage loader installs persistence via a scheduled task (MicrosoftNodeRuntimeUpdater, triggered one minute after logon) and, in the newest campaign, queries an Ethereum smart contract (0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b) to resolve installer, sideload-carrier, and RunPE-carrier URLs, with payloads embedded as Base64/RC4-encoded data inside JPEG steganographic carriers (several hosted on Internet Archive).
A C++ installer (SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268) performs extensive sandbox/VM evasion (process, account, hardware, and VMware/VirtualBox artifact checks) and uses indirect syscalls (via the open-source PigSyscall technique, resolving NTDLL gadgets and API hashes) to evade EDR hooking. It then installs a malicious Chrome/Edge extension using the Phantom Extension/GhostChrome-X technique: it recovers the browser's App-Bound OSCrypt key via a debugger-attached LOAD_DLL_DEBUG_EVENT/pattern-scan of chrome.dll or msedge.dll, then rewrites the Secure Preferences file (enabling developer mode, injecting the malicious extension's settings, and forging protection.macs/*_encrypted_hash/super_mac HMAC integrity values) so Chrome accepts the unauthorized extension without triggering its tamper-detection. The extension (most recently ID ndpbidppejfanjbhfgjlohfanbfbklff, masquerading as "AVSync System Inc.") communicates over a WebSocket channel (/google_ws/) and an HTTP polling channel disguised as .css requests (/google_api/), and supports screenshot capture, tab/cookie/session/local-storage theft, browsing-history collection, full HTML injection, keylogging via input-event listeners, and domain-hash-matched HTTP request interception/redirection. Separately, the installer exfiltrates Login Data, Cookies, Web Data, and derived OSCrypt keys (keys.json) to volmira[.]site and zaviro[.]online, RC4-encrypted via the undocumented SystemFunction032 API.
In its seventh and current campaign (May 2026-present), KREMLIN operators abuse a legitimate SentinelOne binary, SentinelMemoryScanner.exe, to DLL-sideload an unsigned payload disguised as SentinelAgentCore.dll, and also deploy REMCOS RAT and PULSAR RAT alongside the extension. Financial analysis of the Ethereum smart contract's admin wallet (0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6) shows $20,778.97 USDT in / $19,016.96 USDT out across 149 transactions between June 2025 and August 2026, with transaction timing clustering around São Paulo working hours (UTC-3). Portuguese-language code artifacts, lure filenames, mutex names, and the toolkit author handle Kr3mlin4rt1st (first appearing in loader v1.33, February 2026) indicate a Brazil-based, financially motivated criminal operation -- the "KREMLIN" branding is not evidence of Russian state involvement. Elastic Threat Command disrupted over 1,500 active infections by registering the malware's unregistered sandbox-canary domain (creamp1eonlyfans[.]net).
MITRE ATT&CK techniques used in TL-2026-2525
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow
Persistence
T1053 Scheduled Task/Job; T1176 Software Extensions
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
defense-impairment
Affected products and versions in KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom
- Google — Chrome
Vulnerable versions: All Chromium-based releases relying on Secure Preferences/protection.macs integrity, including >=144 with resources.pak-seeded hashing - Microsoft — Edge
Vulnerable versions: Chromium-based Microsoft Edge - SentinelOne — SentinelMemoryScanner.exe (Sentinel Agent component)
Vulnerable versions: Abused as an unsigned-DLL sideloading host for SentinelAgentCore.dll
Remediation for KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom
Immediate actions
- Block and hunt for the identified KREMLIN C2 domains/IPs at DNS and perimeter layers (volmira.site, zaviro.online, luizestrelhashapr.online, lojinhadoluiz.online, cremeb.com, granderevolucao.store, seguranca.versionnova.site, 178.92.162.38, 37.16.74.100, 37.16.74.34, 144.172.112.239, 45.90.13.210, 185.221.23.133)
- Force-remove and blocklist the malicious extension IDs via enterprise Chrome/Edge management (ndpbidppejfanjbhfgjlohfanbfbklff, djodclnjknbpambeaaapadmdfhmbpeog, cdgcjghdeinagopbaobhmaefigoafaaa)
- Audit endpoints for an unsigned SentinelAgentCore.dll co-located with or loaded by SentinelMemoryScanner.exe outside the expected SentinelOne installation directory
- Hunt for the scheduled task 'MicrosoftNodeRuntimeUpdater' and unexpected 'conhost.exe --headless node.exe' process chains
Workarounds
- Disable Chrome/Edge developer mode via enterprise policy (ExtensionDeveloperModeSettings) to close the Secure Preferences tampering surface
- Restrict execution of SentinelMemoryScanner.exe via application control to its signed installation path only
Longer-term hardening
- Deploy EDR with behavioral detection for process hollowing (RunPE) and indirect/hashed syscall usage (PigSyscall-style NTDLL gadget resolution)
- Enforce browser management policy (ExtensionInstallBlocklist, disabled developer mode) to prevent Secure Preferences tampering and unauthorized extension sideloading
- Monitor for debugger attachment to browser processes and LOAD_DLL_DEBUG_EVENT-based App-Bound key extraction as a credential-theft precursor
- Add outbound monitoring for anomalous Ethereum JSON-RPC/Web3 calls from endpoint processes as a dead-drop-resolver C2 indicator
Timeline of KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom
- Earliest RunPE-module JPEG steganographic carrier (output_image_202505.jpg) uploaded to Internet Archive by uploader account 'Radduxx'.
- Campaign 1 ('Codecaudiog A') begins: PowerShell to RunPE to Installer chain delivering the malicious extension, DonutLoader, and PULSAR 1.6.6/1.7.3, C2 at 185.221.23.133.
- Financial activity begins on the Ethereum admin wallet (0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6) that later funds and controls the KREMLIN C2 smart contract.
- Campaign 3 ('Acrobat') begins: Adobe-plugin lure delivering PULSAR 1.7.1/1.7.2 only (no extension) via JavaScript to PowerShell to RunPE to DonutLoader chain.
- Campaign 4 ('Framesync') begins: FrameSync-branded extension (ID djodclnjknbpambeaaapadmdfhmbpeog) with dynamic C2 resolution via an abused Cloudflare Workers endpoint.
- Campaign 5 ('Donalurdesconfeitos to Cremeb') begins, migrating infrastructure across donalurdesconfeitos.site, marialurdes.site, harialurdes.site, and cremeb.com through March 2026.
- First 'KREMLIN' branding (version 1.33) appears in the JSE-encoded loader, attributed to toolkit author 'Kr3mlin4rt1st'.
- Campaign 6 ('Cremeb') begins: QR-code-themed extension (ID cdgcjghdeinagopbaobhmaefigoafaaa) targeting web.whatsapp.com and sicoob.com.br, delivering PULSAR 2.4.5 via Early Cascade Injection into explorer.exe.
- KREMLIN operators deploy their first Ethereum smart contract (0x902Edb...) as a C2/payload dead-drop resolver.
- Rubrik Zero Labs publicly discloses the GhostChrome-X Chrome extension integrity-bypass technique later leveraged by KREMLIN's Phantom Extension installer.
- Campaign 7 ('Ethereum Transition') begins: current smart contract 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b deployed with main-v2/sentinel/sub-module config variables; SentinelMemoryScanner.exe DLL-sideloading installer variant and REMCOS RAT introduced.
- Last transaction recorded in Elastic's observed window on the KREMLIN C2 smart contract's admin wallet ($20,778.97 USDT in / $19,016.96 USDT out across the tracked period).
- Elastic Security Labs publishes REF9334/KREMLIN research; The Hacker News reports 1,515 infected systems (>98% in Brazil) identified after Elastic Threat Command registered the malware's sandbox-canary domain to disrupt infections.
Sources cited for KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
- Malicious Browser Extension: KREMLIN Banking Malware
- Inside GhostChrome-X: A Chrome Extension Integrity Bypass
- The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
- Malware bancario del Kremlin secuestra Chrome y Edge para robar credenciales y tokens de sesión
Detection coverage for TL-2026-2525
As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2525 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.