
Elastic Security Labs has published a detailed technical analysis of KREMLIN, a sophisticated banking malware operation targeting users of Brazilian financial institutions, tracked internally as REF9334. Active since at least May 2025, the campaign begins with lures impersonating a dozen Brazilian banks: victims receive what appears to be a banking document, invoice, or company file — actually a JavaScript file that, when opened, triggers a multi-stage infection chain. The chain ends by installing a malicious browser extension named “AVSync System Inc.” on Google Chrome or Microsoft Edge.
Once installed, the extension steals login credentials, session tokens, and browser cookies. To bypass Chrome and Edge’s built-in integrity protections, KREMLIN tampers with the browser’s Secure Preferences file and regenerates the required HMACs, preventing the browser from detecting or removing the rogue extension through its normal integrity checks. Most unusually, the campaign uses Ethereum smart contracts as a dead-drop resolver: the attacker stores command-and-control (C2) server addresses on the blockchain so they can be swapped at any time without altering the malware itself. Researchers identified the C2 domains volmira[.]site and zaviro[.]online being resolved this way.
How to check if you’re affected
Affected products are Google Chrome and Microsoft Edge on Windows. Open your browser’s extensions page (chrome://extensions or edge://extensions) and look for any extension named “AVSync System Inc.” or with the extension ID ndpbidppejfanjbhfgjlohfanbfbklff. If found, remove it immediately, then change passwords for all online banking and financial accounts, and consider revoking active browser sessions.
