Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

KREMLIN malware forces malicious Chrome and Edge extensions

A banking malware operation active since mid-2025 is using the KREMLIN toolkit to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.

Researchers at Elastic Security Labs say the malware bypasses Chromium integrity checks, making the extensions appear user-approved. The infection starts when a target opens a JavaScript file disguised as a bank receipt, invoice, payment record, or business document. After anti-sandbox checks, the file shows a fake error, downloads Node.js, creates persistence through a scheduled task, and retrieves a payload location from an Ethereum smart contract.

Despite its name, KREMLIN is linked to a Brazilian operation that has run at least seven campaigns since May 2025 using lures impersonating 12 banks. The malware copies an extension into browser profile directories, enables developer mode, and registers it in Chromium’s Secure Preferences. It then recreates the cryptographic integrity checks that protect browser settings, allowing the extension to appear valid without user approval. The extension masquerades as AVSync.

Elastic researchers linked the operation to payloads hidden in JPEG images hosted through the Internet Archive. Recent campaigns deployed the REMCOS remote access tool, while earlier activity used Pulsar RAT; researchers say the change was likely because REMCOS offers more features. Elastic confirmed 1,515 infected systems, almost all in Brazil, and disrupted the campaign by registering a domain used as an anti-sandbox canary.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.