← Back to Crime & Security

Kremlin-linked actors deploy browser extensions to target Brazilian banks

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

BRASILIA — A cyber operation attributed to Kremlin-affiliated threat actors has targeted Brazilian financial institutions by distributing malicious software disguised as legitimate web browser extensions. The campaign, identified on Sept. 15, 2026, utilizes compromised versions of add-ons for Google Chrome and Microsoft Edge to harvest sensitive user data from banking customers across Brazil.

The malware is designed to intercept and exfiltrate critical authentication materials, including login credentials, session tokens, cookies, and other browser-stored data. By embedding malicious code within extensions that appear functional to the end-user, the attackers gain persistent access to victim sessions without triggering standard security alerts. The operation specifically focuses on users of major Brazilian banks, aiming to facilitate unauthorized financial transactions and identity theft.

Security researchers identified the intrusion after detecting anomalous data exfiltration patterns linked to known tactics associated with Russian state-sponsored groups. The malicious extensions were distributed through unofficial channels and potentially compromised legitimate repositories, tricking users into installing them under the guise of productivity or security tools. Once installed, the software operates silently in the background, capturing keystrokes and copying session identifiers that allow attackers to bypass multi-factor authentication mechanisms.

The timing of the attack coincides with a period of heightened digital activity in Brazil's financial sector. While no specific bank has publicly confirmed a breach directly linked to this specific campaign, the widespread distribution of the malicious extensions suggests a broad-based attempt to compromise individual accounts rather than a targeted strike against a single institution's core infrastructure.

Brazilian cybersecurity authorities have issued urgent warnings to financial institutions and consumers to audit their browser settings and remove any unrecognized extensions. Banks are advised to monitor for unusual login attempts and session anomalies that may indicate compromised credentials. The incident underscores the evolving nature of threats targeting the financial sector, where attackers increasingly rely on social engineering and supply chain compromises rather than direct network intrusions.

The full scope of the data stolen remains unclear as investigators work to trace the extent of the compromise. It is not yet known how many users have been affected or whether any funds have been successfully diverted. Questions remain regarding the specific methods used to distribute the malicious extensions and whether other financial sectors in Latin America are facing similar threats. Authorities continue to assess the potential for further escalation as the operation appears to be in an active phase.

Discussion

0 / 2000