Elastic Security Labs documented REF9334, a Brazil-focused banking-malware operation active since at least May 2025 that delivers the KREMLIN toolkit through Portuguese-language document lures impersonating financial institutions. Multi-stage JavaScript, Node.js, and C++ components use anti-analysis checks, RunPE execution, and SentinelOne DLL sideloading; the campaign has also deployed PULSAR and REMCOS remote-access trojans.
KREMLIN silently installs a malicious Chromium extension named “AVSync System Inc.” by modifying Chrome and Edge Secure Preferences and regenerating browser integrity values. The extension can collect saved credentials, cookies, session tokens, browser storage, page content, screenshots, and keystrokes. Its operators use Ethereum smart contracts as resilient dead-drop resolvers for mutable payload and C2 configuration, alongside Archive.org-hosted JPEG carriers. After researchers registered an unclaimed network-canary domain, 1,515 infected hosts checked in—98.75% of them geolocated in Brazil—before implants identified the environment as a sandbox and halted later-stage activity.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
REF9334 transitioned to Ethereum smart contracts as dead-drop resolvers for dynamically updated payload-hosting and command-and-control locations. Newer infection chains paired the malicious browser extension with REMCOS RAT.
Researchers identified the first full KREMLIN branding in a loader dated February 8, 2026. The loader was version 1.33 and credited an author using the handle Kr3mlin4rt1st.
The September 2025 Framesync campaign used extensions masquerading as FrameSync Driver System and FrameSync Plugin Project, showing the browser-extension capability preceded KREMLIN branding.
REF9334's June 2025 Codecaudiog campaigns delivered PULSAR RAT and, in some variants, malicious browser extensions. The operation was subsequently linked to at least seven campaigns beginning in June 2025.
Elastic Security Labs tracked the Brazilian-focused REF9334 banking-malware operation as active from at least May 2025. The operation used Portuguese-language lures impersonating Brazilian financial institutions to deliver its malware.
Elastic researchers registered the previously unregistered KREMLIN network-canary domain, causing implants that contacted it to treat their environment as simulated and terminate before later stages. They observed 1,515 check-ins, with approximately 98.75% geolocated in Brazil.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 101 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceelastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.