Introduction
A new banking‑oriented malware operation has been observed in the wild since mid‑2025. The campaign distinguishes itself by employing a custom toolkit, named KREMLIN, to bypass browser defenses and push malicious extensions onto victims' Chrome and Edge browsers. Those extensions act as data‑stealing agents, capturing login credentials, session tokens, and additional sensitive information. The technique expands the attack surface beyond traditional payload delivery, leveraging the trust users place in browser extensions.
What Happened
Analysts identified that the KREMLIN toolkit forces the installation of hostile extensions for both Google Chrome and Microsoft Edge. Once present, the extensions silently collect authentication data and session identifiers, then exfiltrate them to the operators. The malware’s primary target appears to be banking customers, though any user of the affected browsers could be compromised.
Technical Details
KREMLIN operates by exploiting the extension installation workflow of Chromium‑based browsers. Rather than relying on user interaction, the toolkit injects code that triggers the browser’s extension‑install API, presenting the malicious package as a legitimate add‑on. The extensions request permissions that include access to browsing history, cookies, and form data, enabling them to harvest:
- Stored usernames and passwords for online banking portals.
- Session cookies that maintain authenticated sessions.
- Any other data the browser makes available to extensions with elevated privileges. The stolen information is then transmitted to command‑and‑control servers controlled by the threat actors. No CVE identifiers were disclosed, indicating the toolkit may be leveraging existing, documented extension‑install mechanisms rather than a zero‑day vulnerability.
Who Is Affected
The immediate victims are users of Google Chrome and Microsoft Edge who receive the forced extension install. Because both browsers dominate the consumer and enterprise markets, the potential victim pool is extensive. Organizations that allow employees to browse the web with these browsers are at risk, especially if they do not enforce strict extension whitelisting policies. Financial institutions should be particularly concerned, as the stolen credentials can be used to access customer accounts directly.
Why It Matters
Credential and session‑token theft bypasses multi‑factor authentication that relies on the possession of a valid session. Once attackers obtain a live session token, they can act as the legitimate user without triggering additional authentication steps. This capability undermines traditional security controls and accelerates the timeline from compromise to monetary loss. Moreover, the use of a toolkit that automates extension installation demonstrates a scalable approach that can be repurposed for other malicious objectives.
Recommended Actions
- Enforce Extension Whitelisting: Configure Chrome and Edge policies to allow only approved extensions. Block all unsigned or unknown add‑ons.
- Monitor Extension Install Events: Deploy endpoint detection and response (EDR) solutions that flag sudden extension installations, especially those originating from non‑administrative processes.
- Restrict Browser Privileges: Apply least‑privilege principles to browser processes. Prevent standard users from installing extensions without administrator approval.
- Conduct Credential Hygiene Audits: Encourage users to change passwords regularly and to review active sessions in banking portals. Implement session‑revocation mechanisms where possible.
- Educate End‑Users: Inform staff and customers about the risk of unsolicited browser extensions and the signs of credential theft.
- Update Security Tooling: Ensure web‑gateway and proxy solutions can inspect extension traffic and block known malicious payloads.
Conclusion
The KREMLIN‑driven operation illustrates how threat actors can weaponize legitimate browser features to harvest high‑value credentials. By forcing the installation of malicious Chrome and Edge extensions, the campaign sidesteps many traditional defenses and directly targets the data most valuable to financial fraud. Organizations must tighten extension controls, monitor for anomalous install activity, and reinforce credential security to mitigate this emerging threat.
Sources
- BleepingComputer: https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/