CTIPilot

KREMLIN

malware · malware:kremlin single-source

Malicious Chrome/Edge browser-extension toolkit (named by its own author) that forges Chromium's Secure Preferences integrity HMACs to sideload an unauthorized extension outside the Web Store; resolves payload URLs via an Ethereum smart-contract dead-drop resolver. Attributed to REF9334, targeting Brazilian banking users (Elastic Security Labs, 2026-09-14). The name is the author's own coinage; Elastic states nothing about the operation indicates a Russian nexus.

Coverage timeline
1
first 2026-09-21 → last 2026-09-21
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
5
see Co-occurring entities below
ATT&CK techniques
9
pinned v19.2 · see below

ATT&CK techniques

9 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Persistence TA0003

T1176Software Extensions×1

Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Stealth TA0005

T1027.007Obfuscated Files or Information: Dynamic API Resolution×1

Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Defense Impairment TA0112

T1553Subvert Trust Controls×1

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Credential Access TA0006

T1555.003Credentials from Password Stores: Credentials from Web Browsers×1

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Discovery TA0007

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Command and Control TA0011

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-21/ref9334-kremlin-chromium-secure-preferences-hmac-forge · ATT&CK page ↗

Story timeline

  1. 2026-09-21REF9334/KREMLIN forges Chromium's own Secure Preferences integrity hashes to silently install a banking-fraud browser extension outside the Web Store, resolving C2 through an Ethereum smart contract
    active-threatsElastic Security Labs: a Brazilian banking-fraud toolkit defeats Chromium's extension-integrity check by extracting the browser's own signing keys from memory

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

used by

Where this entity is cited

  • active-threats1

Source distribution

  • elastic.co1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about KREMLIN (1)

2026-09-21 · view entry permalink →

NOTABLENATOB2

REF9334/KREMLIN forges Chromium's own Secure Preferences integrity hashes to silently install a banking-fraud browser extension outside the Web Store, resolving C2 through an Ethereum smart contract

Elastic Security Labs has tracked REF9334, a Brazilian-banking-focused operation, across seven campaigns since May 2025 (Elastic Security Labs, 2026-09-14). Its toolkit, KREMLIN, a name the malware's own author chose; Elastic states nothing about the operation is actually Russian: Portuguese-language lures and code comments, and Ethereum transaction timestamps its executive summary describes as clustering during São Paulo working hours, its technical analysis separately finds only a small minority of transactions falling in late-night hours, none extending into early morning, and reasons this is more consistent with operators working late than waking before dawn, corroborating rather than contradicting the same São Paulo conclusion, instead point to Brazil. KREMLIN's infection chain begins with an obfuscated, multi-stage JavaScript loader (trivially de-obfuscated by an LLM, per Elastic) that checks sandbox indicators such as desktop file count and WMI process count before decoding a second stage via certutil and downloading Node.js to run it. That second stage installs persistence disguised as a scheduled task named "MicrosoftNodeRuntimeUpdater," then queries an Ethereum smart contract for three configuration parameters: a main module URL, a .NET RunPE injector hidden as Base64-encoded JPEG data, and a legitimate SentinelOne SentinelMemoryScanner.exe binary abused for DLL sideloading, a technique Symantec first documented in a separate Seedworm intrusion. The main C++ installer resolves NTDLL syscall numbers indirectly, by correlating export names against the .pdata exception-directory RUNTIME_FUNCTION table rather than parsing Nt*/Zw* stubs directly, and runs extensive sandbox and analysis-tool checks (process-name blacklists, a hardcoded username blacklist, CPU/RAM thresholds, a deliberately-unregistered-domain network canary, and VMware/VirtualBox artifact checks) before proceeding.

The extension-installation step is the toolkit's most technically striking element, documented in detail by Synacktiv's "Phantom Extension" research and rarely seen deployed in the wild: KREMLIN waits for the browser to close, or for the user to idle for two minutes and then force-terminates it if still open, then relaunches the browser under a debugger specifically to catch the LOAD_DLL_DEBUG_EVENT for chrome.dll or msedge.dll, scans that module's memory for a string cross-reference to OSCrypt.AppBoundProvider.Decrypt.ResultCode to locate and read the in-memory App-Bound encryption key via ReadProcessMemory, and separately recovers the legacy DPAPI-protected OSCrypt key from Local State. Using the recovered keys plus a seed extracted from resources.pak, a sibling file in the Chrome installation directory, KREMLIN regenerates the legacy HMAC and the newer OSCrypt-encrypted SHA-256 hash that Chromium's Secure Preferences integrity mechanism requires, then manually copies the extension's files into the browser profile and edits Secure Preferences directly (enabling developer mode, registering the extension under extensions.settings.<id>, and writing the forged protection.macs values) installing the extension exactly as if a user had approved it through the Web Store, with no user interaction and no visible warning. Elastic disrupted over 1,500 infections by registering the operation's network-canary kill-switch domain.

Triage: extensions are routinely installed and removed through the Web Store's own mechanism, so an extension's mere presence is not the signal; the discriminator is provenance: an extension entry in Secure Preferences with no matching Web Store installation event, or extensions.settings entries whose protection.macs values were written outside a normal browser-update or user-installation flow.

Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs and App-Bound encrypted hashes.

KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser's profile directories and registers it in the Secure Preferences file.

Threat Command temporarily disrupted over 1,500 (and counting) infections in this reported campaign by registering the network canary (kill switch) domain

Elastic Security Labs 2026-09-14
threat21 Sep 04:46Zsingle-sourceOpen finding ↗