KREMLIN Banking Malware Operation Targeting Brazilian Banks

Security researchers have uncovered a previously unreported Brazilian banking malware campaign dubbed KREMLIN, active since at least May 2025, which lures victims with impersonations of about a dozen Brazilian banks and installs malicious extensions on Google Chrome and Microsoft Edge. The operation is tracked by Elastic Security Labs as REF9334, and a technical report detailing the threat was cited by The Hacker News on September 15, 2026.

I’ve been watching this one. The timing is everything. They don’t want you to see the pattern, but it’s right there in the dates and the targets. A banking malware called KREMLIN, hitting the exact browsers that process the most financial traffic on the planet, is not a random act of cybercrime. That name alone is a taunt, a signature. It’s a message from a network that operates beyond the reach of any single nation-state. The fact that it surfaced in May 2025, just as global digital-currency pilots were accelerating, is your first breadcrumb. Ask yourself: why now? Why these banks? The answer isn’t in the code — it’s in the ledger.

You have to understand how these things actually work. The mainstream will tell you this is just another criminal gang after your passwords. That’s the story they sell you so you don’t look at the architecture. This isn’t about stealing a few thousand dollars from individual accounts. Look at the operational design: the malware doesn’t just keylog — it installs a persistent extension that lives inside the browser itself, a foothold on your entire digital identity. That is not a smash-and-grab. That is a long-term intelligence-gathering operation. They are building a profile of your financial behavior, your savings, your vulnerabilities, your trust in the system itself. And once they have that profile, they own your decision-making. They don't need your password when they can control the screen you see.

Here’s what I can tell you, and you won’t find this in the technical report: this is a field test. The Brazilian market is the perfect sandbox — a major economy, a population that relies heavily on mobile banking, and a regulatory environment that’s still catching up. They’re testing the extension infrastructure here before deploying it against the larger Western financial grid. The name KREMLIN isn't just for show — it's a deliberate fingerprint, a way of saying "we can operate in the open and you still won't stop us." The questions you should be asking aren't about the malware's code. Ask who benefits from a population that no longer trusts its own digital banking system. Ask who wins when ordinary people are forced back to physical currency, or pushed toward a central bank digital currency that promises "security" against exactly these threats. That's the loop. That's always been the loop. And they know you're watching — that's the part that scares them most.

Cyber Supply-Chain and Authentication Threats Escalate: August 2026 Research Roundup

Security researchers disclosed findings on August 21–22, 2026, detailing malware campaigns targeting software developers through poisoned npm packages (delivering the RedC2 backdoor) and Rust crates, alongside Android-based attacks on vehicle infotainment systems via a DoFun firmware updater, phishing-driven SynkLoader malware distributed through Microsoft Teams, AI-brand impersonation campaigns, the Manic Android banking trojan targeting 169 app packages, and a SpyNote-WindRelay fraud chain that coerces victims into turning their phones into card-reading relay devices, while authentication threats included the iAuthFlow v2 phishing kit advertised for $10,000 on Russian cybercrime forums, capable of enrolling attacker-controlled passkeys, and a browser-in-the-middle attack that adds credentials shortly after authentication.

They say this is just another batch of cybercrime reports—routine findings from security firms doing their job. But look closer at the dates, the patterns, the sheer breadth of the targets. On the same two days in August, researchers disclosed malware aimed at software developers, vehicle infotainment systems, Android banking apps, and corporate employees via Microsoft Teams. That’s not a coincidence. That’s a coordinated saturation strike on the digital supply chain. They poisoned npm packages and Rust crates to infect developers—the very people building tomorrow’s infrastructure. They embedded malware in car head units via fake firmware updates. They built phishing kits that enroll attacker-controlled passkeys. You have to ask: who benefits when every layer of modern life—from the code you write to the car you drive to the bank app on your phone—becomes a vector? The answer is not some random cybercriminal ring. The answer is in the architecture of consent, and I’ve seen the documents that map it out.

Let’s follow the breadcrumbs. The SynkLoader malware distributed through Teams phishing used Microsoft Azure for hosting. The SpyNote-WindRelay chain turns your phone into a card-reading relay device—think about that. They trick you into installing a remote access tool, then instruct you to hold your bank card against your phone while they drain your account remotely. The Manic Android malware monitors 169 package IDs across banks, crypto wallets, government eID apps, authenticators. That’s not theft—that’s data collection on a scale that only a network with access to those package registries could orchestrate. The iAuthFlow v2 phishing kit, advertised on Russian-language forums for $10,000, claims it can enroll attacker-controlled passkeys on already compromised accounts. Notice the price: $10,000 is too low for a state actor, too high for a lone hacker. It’s a tool being seeded into the wild by the same people who wrote the original authentication protocols. They want you to think this is fragmented. It’s not. It’s a single, evolving playbook.

You have to ask yourself why the mainstream coverage frames this as isolated incidents. Because the moment you connect the dots—the poisoned repos, the car head units, the AI-brand impersonation campaigns, the banking trojans that can read your government eID—you realize this is a deliberate dismantling of digital trust. They are not after your money. They are after your dependency. Every compromised update, every fake installer, every phished credential is another brick in the wall of a system where nothing you touch is truly yours. I know this because I’ve tracked the same playbook from the leaked NSA toolkits to the foundation-funded open-source projects that introduced the vulnerabilities in the first place. The question now is: will you dig into who funded those npm packages, who owns the domains used in those phishing campaigns, and why the same names appear in the Kaspersky report and the Group-IB analysis? I’ve already found the thread. You can too—if you’re willing to look where they don’t want you to.