KREMLIN Banking Malware Bypasses Chrome and Edge Security to Install Malicious Extensions
A banking malware campaign active since mid-2025 is using a toolkit called KREMLIN to install malicious Chrome and Microsoft Edge extensions that steal credentials, session tokens, cookies, and other sensitive data.
Researchers at Elastic Security Labs found that the malware can bypass Chromium’s browser integrity mechanisms, causing the extensions to load as though they had been approved by the user.
The campaign begins when a targeted user opens a JavaScript file disguised as a bank receipt, invoice, payment record, or other business document.
After passing anti-sandbox checks, the file displays a bogus error while downloading Node.js, creating persistence through a scheduled task, and retrieving the location of additional payloads from an Ethereum smart contract.
Despite its name, KREMLIN is linked to a Brazilian operation responsible for at least seven campaigns that have used decoys impersonating 12 banks since May 2025.
How KREMLIN installs malicious Chrome and Edge extensions
KREMLIN’s most notable feature is its ability to install extensions on Chrome and Edge without requesting approval from the user.
The malware waits for the browser to close, or exits the browser when it detects that it is idle. It then copies the extension to the browser’s profile directory, enables developer mode, and adds the extension to Chromium’s secure settings.
To conceal the changes, KREMLIN uses the encryption keys that browsers rely on to protect sensitive data. It also recreates the integrity checks Chrome uses to detect unauthorized changes to browser settings.
This process makes the malicious extension appear valid to the browser, even though the user did not authorize it. The technique was previously documented, but researchers say it is rarely used by malware.
“KREMLIN uses a well-documented technique rarely seen in malware: it manually copies the extension to the browser’s profile directory and registers it in a secure configuration file,” Elastic explains.
“Chromium protects these entries with cryptographic integrity checks, so the malware must obtain the necessary keys and regenerate the associated HMAC and cryptographic hashes.”
What the malicious AVSync extension can do
Once installed, the extension impersonates AVSync and can perform the following actions:
- Steal cookies, local storage, and session storage
- Log text entered into forms, including passwords
- Capture screenshots and page source
- List open tabs and browsing history
- Intercept the body and headers of HTTP requests
- Inject attacker-controlled HTML into websites
- Redirect clicks to destinations chosen by the attacker
- Receive commands through a WebSocket connection
In addition to installing malicious extensions, the KREMLIN toolkit acts as an information stealer. It can archive and exfiltrate browser databases, cookies, installed extensions, and cryptographic keys bound to applications that are needed to decrypt protected data.

Source: Elastic
Ethereum smart contracts help control the attack
Elastic Security Labs found that the KREMLIN campaign uses Ethereum smart contracts as dead-drop resolvers. The attackers also exploit the Internet Archive to host payloads hidden inside JPEG images.
In recent campaigns, the attackers deployed the REMCOS remote access tool. Earlier operations delivered the Pulsar RAT. According to the researchers, the switch was likely made because REMCOS offers more features.
Researchers identified Ethereum wallets that deploy and update smart contracts by connecting infrastructure activity with code artifacts.
According to the researchers, one wallet processed approximately 20,800 USDT, or Tether, in transfers, while another processed 19,000 USDT in transfers. Elastic confirmed 1,515 infected systems, most of them located in Brazil.
Elastic disrupts the KREMLIN malware campaign
Elastic disrupted the current KREMLIN campaign by registering a domain used by the malware as an anti-sandbox canary. This caused the loader to stop with a false flag on infected systems.
Elastic Security Labs has shared details about the tactics and techniques used in the KREMLIN attacks, along with a series of indicators of compromise.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



