# KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials

> Elastic Security Labs (tracked as REF9334) exposed KREMLIN, a Brazilian banking-malware toolkit active since May 2025 that impersonates about a dozen Brazilian banks to sideload a malicious Chrome/Edge extension using the publicly documented Phantom Extension/GhostChrome-X Secure Preferences integrity bypass. Later campaigns abuse a legitimate SentinelOne binary (SentinelMemoryScanner.exe) to DLL-sideload an unsigned payload (SentinelAgentCore.dll) and resolve C2 endpoints via an Ethereum smart contract acting as a dead-drop resolver. Elastic identified 1,515 infected systems (>98% in Brazil) via a disrupted network-canary domain.

- **Published:** 2026-09-15T00:00:00Z
- **Last reviewed:** 2026-09-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2525
- **ID:** TL-2026-2525
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** REF9334
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

KREMLIN is a Brazilian banking-malware ecosystem tracked by Elastic Security Labs under the moniker REF9334, active since at least May 2025 across seven distinct, evolving campaigns. Infection begins with a multi-stage obfuscated JavaScript loader (delivered as a fake banking/invoice document) that performs sandbox evasion (desktop file count, running process count, and a network canary check against an unregistered domain), decodes an embedded payload via certutil, and downloads a Node.js runtime. A second-stage loader installs persistence via a scheduled task (MicrosoftNodeRuntimeUpdater, triggered one minute after logon) and, in the newest campaign, queries an Ethereum smart contract (0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b) to resolve installer, sideload-carrier, and RunPE-carrier URLs, with payloads embedded as Base64/RC4-encoded data inside JPEG steganographic carriers (several hosted on Internet Archive).

A C++ installer (SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268) performs extensive sandbox/VM evasion (process, account, hardware, and VMware/VirtualBox artifact checks) and uses indirect syscalls (via the open-source PigSyscall technique, resolving NTDLL gadgets and API hashes) to evade EDR hooking. It then installs a malicious Chrome/Edge extension using the Phantom Extension/GhostChrome-X technique: it recovers the browser's App-Bound OSCrypt key via a debugger-attached LOAD_DLL_DEBUG_EVENT/pattern-scan of chrome.dll or msedge.dll, then rewrites the Secure Preferences file (enabling developer mode, injecting the malicious extension's settings, and forging protection.macs/*_encrypted_hash/super_mac HMAC integrity values) so Chrome accepts the unauthorized extension without triggering its tamper-detection. The extension (most recently ID ndpbidppejfanjbhfgjlohfanbfbklff, masquerading as "AVSync System Inc.") communicates over a WebSocket channel (/google_ws/) and an HTTP polling channel disguised as .css requests (/google_api/), and supports screenshot capture, tab/cookie/session/local-storage theft, browsing-history collection, full HTML injection, keylogging via input-event listeners, and domain-hash-matched HTTP request interception/redirection. Separately, the installer exfiltrates Login Data, Cookies, Web Data, and derived OSCrypt keys (keys.json) to volmira[.]site and zaviro[.]online, RC4-encrypted via the undocumented SystemFunction032 API.

In its seventh and current campaign (May 2026-present), KREMLIN operators abuse a legitimate SentinelOne binary, SentinelMemoryScanner.exe, to DLL-sideload an unsigned payload disguised as SentinelAgentCore.dll, and also deploy REMCOS RAT and PULSAR RAT alongside the extension. Financial analysis of the Ethereum smart contract's admin wallet (0x5C32A09873be70a92fd8bB5A9fED7967dE06BdE6) shows $20,778.97 USDT in / $19,016.96 USDT out across 149 transactions between June 2025 and August 2026, with transaction timing clustering around São Paulo working hours (UTC-3). Portuguese-language code artifacts, lure filenames, mutex names, and the toolkit author handle Kr3mlin4rt1st (first appearing in loader v1.33, February 2026) indicate a Brazil-based, financially motivated criminal operation -- the "KREMLIN" branding is not evidence of Russian state involvement. Elastic Threat Command disrupted over 1,500 active infections by registering the malware's unregistered sandbox-canary domain (creamp1eonlyfans[.]net).

## MITRE ATT&CK

- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1176 Software Extensions
- T1055 Process Injection
- T1036 Masquerading
- T1497 Virtualization/Sandbox Evasion
- T1574 Hijack Execution Flow
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518 Software Discovery
- T1071 Application Layer Protocol

## Sources

- [KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)
- [Malicious Browser Extension: KREMLIN Banking Malware](https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware)
- [Inside GhostChrome-X: A Chrome Extension Integrity Bypass](https://zerolabs.rubrik.com/blog/inside-ghostchrome-x-chrome-extension-integrity-bypass)
- [The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions](https://www.hendryadrian.com/the-extension-you-never-installed-kremlin-forges-chromes-own-integrity-checks-to-steal-banking-sessions/)
- [KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens](https://nuclearcoffee.org/kremlin-banking-malware-hijacks-chrome-and-edge-to-steal-credentials-and-session-tokens/)
- [Malware bancario del Kremlin secuestra Chrome y Edge para robar credenciales y tokens de sesión](https://blog.elhacker.net/2026/09/malware-bancario-del-kremlin-secuestra.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2525
