Skip to content

KREMLIN

KREMLIN is a Brazil-focused banking trojan toolkit associated with the REF9334 cybercrime operation, active since at least May 2025.

Profile source: Mallory opens in a new tab

KREMLIN

Family profile

KREMLIN is a Brazil-focused banking trojan toolkit associated with the REF9334 cybercrime operation, active since at least May 2025. It targets Brazilian banking users through Portuguese-language lures impersonating financial institutions, invoices, receipts, payment records, and corporate documents. Infection begins when a victim executes a disguised JavaScript file, which performs sandbox checks and launches a multi-stage loader chain.

KREMLIN establishes Windows persistence with a scheduled task, uses anti-analysis checks, and retrieves mutable payload and command-and-control configuration through Ethereum smart contracts. Later activity incorporated DLL sideloading through a legitimate security-product component. The toolkit installs malicious Chromium extensions, including AVSync, directly into Google Chrome and Microsoft Edge profiles. It bypasses Chromium extension-integrity protections by modifying protected browser preferences and associated validation data, allowing the extension to appear authorized without installation through an official extension store.

The malicious extension and supporting components steal saved browser credentials, cookies, session tokens, browser storage, encryption keys, typed form data, screenshots, tab information, page content, and other Chromium profile data. Extension functionality also supports keylogging, HTTP-request interception, HTML injection, and attacker-controlled browser redirection, enabling account takeover and transaction fraud. KREMLIN has also been deployed alongside Pulsar RAT and Remcos RAT in some campaigns. Confirmed victim telemetry indicates that the overwhelming majority of affected systems were located in Brazil.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 16, 2026
Feed role
C2
Host form
0 IP / 17 hostnames

Leading locations

  • US5
  • CH2
  • CY1
  • DE1
  • NL1

Leading providers

  • Cloudflare, Inc.2
  • Namecheap, Inc.2
  • SKN Subnet & Telecom Ltd2
  • BL Networks1
  • DigitalOcean, LLC1
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 8
  • Anycast 3

Reported operators

Threat actors

1 named in public reporting
REF9334

Elastic Security Labs describes REF9334 as a Brazilian banking-malware operation active since May 2025. The toolkit is named KREMLIN by its author, Kr3mlin4rt1st, and deploys a malicious Chromium extension while using Node.js, scheduled-task persistence, DLL sideloading, and Ethereum smart contracts for configuration and payload delivery.

MITRE ATT&CK

KREMLIN in ATT&CK

48 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.