KREMLIN malware bypasses browser checks to install malicious Chrome and Edge extensions

0
28
KREMLIN malware bypasses browser checks to install malicious Chrome and Edge extensions Credit: Bleeping Computer
KREMLIN malware bypasses browser checks to install malicious Chrome and Edge extensions Credit: Bleeping Computer

A banking malware campaign active since mid-2025 is using a toolkit called KREMLIN to secretly install malicious extensions on Chrome and Edge, allowing attackers to steal credentials, session tokens and other sensitive information.

Researchers at Elastic Security Labs found that the malware can bypass Chromium’s integrity protections and make the extensions appear as if they were approved by the user.

The attack begins when a victim opens a JavaScript file disguised as a bank receipt, invoice, payment record or business document. After checking whether it is running in a sandbox, the file can download Node.js, create persistence through a scheduled task and retrieve the location of additional payloads through an Ethereum smart contract.

Despite its name, KREMLIN has been linked to a Brazilian operation that has conducted at least 7 campaigns since May 2025 using lures impersonating 12 banks.

One of its key capabilities is installing extensions without user approval. The malware waits for the browser to close or terminates it when the system is idle, then copies the extension into the browser’s profile directories.

It subsequently enables developer mode and registers the extension in Chromium’s Secure Preferences. The malware also retrieves encryption keys used by the browser and recreates the integrity checks needed to make the modified preferences appear legitimate.

Once installed, the extension disguises itself as AVSync and can steal cookies, local and session storage, record keystrokes entered into forms, capture screenshots and page source, and monitor open tabs and browsing history.

It can also intercept HTTP request bodies and headers, inject attacker-controlled HTML into websites, redirect clicks and receive commands through a WebSocket connection.

KREMLIN also functions as an information stealer, capable of collecting browser databases, cookies, installed extensions and App-Bound cryptographic keys used to protect sensitive browser data.

Researchers found that the campaigns use Ethereum smart contracts as dead-drop resolvers and the Internet Archive to host payloads concealed inside JPEG images. Recent campaigns have deployed the REMCOS remote access tool, while earlier operations used Pulsar RAT.

Elastic identified 1,515 infected systems, with almost all located in Brazil. Researchers also traced an Ethereum wallet associated with the campaign that handled around 20,800 USDT in incoming transfers and 19,000 USDT in outgoing transfers.

Elastic disrupted the latest campaign by registering a domain used by the malware as an anti-sandbox canary. This caused the loader to stop after falsely identifying targeted systems as unsuitable for infection.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.