Last seven days
- First activity
- Sep 16, 2026
- Last activity
- Sep 16, 2026
- Feed role
- C2
- Host form
- 0 IP / 17 hostnames
KREMLIN is a Brazil-focused banking trojan toolkit associated with the REF9334 cybercrime operation, active since at least May 2025.
Profile source: Mallory opens in a new tabKREMLIN
KREMLIN is a Brazil-focused banking trojan toolkit associated with the REF9334 cybercrime operation, active since at least May 2025. It targets Brazilian banking users through Portuguese-language lures impersonating financial institutions, invoices, receipts, payment records, and corporate documents. Infection begins when a victim executes a disguised JavaScript file, which performs sandbox checks and launches a multi-stage loader chain.
KREMLIN establishes Windows persistence with a scheduled task, uses anti-analysis checks, and retrieves mutable payload and command-and-control configuration through Ethereum smart contracts. Later activity incorporated DLL sideloading through a legitimate security-product component. The toolkit installs malicious Chromium extensions, including AVSync, directly into Google Chrome and Microsoft Edge profiles. It bypasses Chromium extension-integrity protections by modifying protected browser preferences and associated validation data, allowing the extension to appear authorized without installation through an official extension store.
The malicious extension and supporting components steal saved browser credentials, cookies, session tokens, browser storage, encryption keys, typed form data, screenshots, tab information, page content, and other Chromium profile data. Extension functionality also supports keylogging, HTTP-request interception, HTML injection, and attacker-controlled browser redirection, enabling account takeover and transaction fraud. KREMLIN has also been deployed alongside Pulsar RAT and Remcos RAT in some campaigns. Confirmed victim telemetry indicates that the overwhelming majority of affected systems were located in Brazil.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Elastic Security Labs describes REF9334 as a Brazilian banking-malware operation active since May 2025. The toolkit is named KREMLIN by its author, Kr3mlin4rt1st, and deploys a malicious Chromium extension while using Node.js, scheduled-task persistence, DLL sideloading, and Ethereum smart contracts for configuration and payload delivery.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.