№259|04:54 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Banking Malware KREMLIN Force-Installs Browser Extensions to Steal Credentials from Chrome and Edge

A Brazilian banking malware operation called KREMLIN has been silently force-installing malicious extensions on Chrome and Edge since mid-2025, bypassing Chromium's cryptographic integrity checks to steal credentials, session tokens, and sensitive user data, according to Elastic Security Labs.

MS
Marc Sabatini
SEP 16, 2026 · 03:01 PM ET · 3 MIN READ
Photo by Rubaitul Azad on Unsplash

A Brazilian banking malware operation has been deploying a toolkit called KREMLIN since mid-2025 to silently install malicious extensions on Google Chrome and Microsoft Edge — bypassing the browsers' built-in integrity checks without any user approval, according to researchers at Elastic Security Labs.

The campaign, first reported by BleepingComputer, has been linked to at least seven separate campaigns since May 2025, using lures that impersonate 12 different banks to trick targets into opening malicious files.

The infection begins when a target opens a JavaScript file disguised as a bank receipt, invoice, payment record, or business document. After passing anti-sandbox checks, the file triggers a fake error message while simultaneously downloading Node.js, establishing persistence through a scheduled task, and retrieving a secondary payload location from an Ethereum smart contract.

KREMLIN's defining capability is its ability to install browser extensions on Chrome and Edge without prompting the user. The malware waits for the browser to close — or terminates it when it detects idle status — then copies the extension into the application's profile directories. It enables developer mode, registers the extension in Chromium's Secure Preferences file, and uses the browser's own encryption keys to regenerate the cryptographic integrity checks that Chrome relies on to detect unauthorized changes.

The result is a malicious extension that appears fully legitimate to the browser despite never being sanctioned by the user.

"KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser's profile directories and registers it in the Secure Preferences file," Elastic Security Labs explained in its research. "Because Chromium protects these entries with cryptographic integrity checks, the malware must retrieve the required keys and regenerate the associated HMACs and encrypted hashes."

Once installed, the extension masquerades as a tool called AVSync. From that position, it steals cookies, local storage, and session data; keyloggs text entered into forms, including passwords; captures screenshots and page source; enumerates open tabs and browsing history; intercepts HTTP request bodies and headers; injects attacker-controlled HTML into websites; and redirects clicks to attacker-selected destinations.

Beyond the extension, the KREMLIN toolkit also functions as a standalone info-stealer, capable of archiving and exfiltrating browser databases, cookies, installed extensions, and the App-Bound cryptographic keys required to decrypt protected data.

The operation's infrastructure relies on Ethereum smart contracts as dead-drop resolvers — a technique that makes command-and-control infrastructure more difficult to take down — and abuses the Internet Archive to host payloads hidden inside JPEG images. In more recent campaigns, the threat actor deployed the REMCOS remote access tool, replacing the earlier Pulsar RAT; Elastic researchers attributed the switch to REMCOS being more feature-rich.

Elastic's infrastructure analysis identified the Ethereum wallet used to deploy and update the smart contracts. That wallet handled approximately 20,800 USDT in incoming transfers and roughly 19,000 USDT in outgoing transfers, according to the researchers.

Elastic Security Labs confirmed 1,515 infected systems, nearly all located in Brazil. The firm disrupted the current KREMLIN campaign by registering a domain the malware used as an anti-sandbox canary, causing the loader to halt on systems that would otherwise have been infected.

Despite bearing a name that might suggest an Eastern European origin, Elastic's researchers tied the operation firmly to Brazil. The firm has published the tactics, techniques, and a set of indicators of compromise to assist defenders in detecting and responding to KREMLIN activity.

The campaign underscores a persistent gap in browser security architecture: while Chromium's integrity mechanisms are designed to flag unauthorized changes to extension preferences, a sufficiently determined attacker with local code execution can reconstruct those checks from the inside — making silent extension installation a viable, if technically demanding, avenue for credential theft.

Disclaimer

MS
━ ABOUT THE REPORTER
Marc Sabatini

Marc Sabatini is a staff writer at TechEchelon covering enterprise software, cybersecurity, and the regulatory beats that shape both. He focuses on the deal flow and policy decisions that move markets.

More from Marc
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime