Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Malware

Banking Malware Leverages KREMLIN Toolkit to Force‑Install Malicious Browser Extensions

17 September 2026 LetsDefend Infosec 4 min read

Introduction

A new banking‑oriented malware operation has been observed in the wild since mid‑2025. The campaign distinguishes itself by employing a custom toolkit, named KREMLIN, to bypass browser defenses and push malicious extensions onto victims' Chrome and Edge browsers. Those extensions act as data‑stealing agents, capturing login credentials, session tokens, and additional sensitive information. The technique expands the attack surface beyond traditional payload delivery, leveraging the trust users place in browser extensions.

What Happened

Analysts identified that the KREMLIN toolkit forces the installation of hostile extensions for both Google Chrome and Microsoft Edge. Once present, the extensions silently collect authentication data and session identifiers, then exfiltrate them to the operators. The malware’s primary target appears to be banking customers, though any user of the affected browsers could be compromised.

Technical Details

KREMLIN operates by exploiting the extension installation workflow of Chromium‑based browsers. Rather than relying on user interaction, the toolkit injects code that triggers the browser’s extension‑install API, presenting the malicious package as a legitimate add‑on. The extensions request permissions that include access to browsing history, cookies, and form data, enabling them to harvest:

  • Stored usernames and passwords for online banking portals.
  • Session cookies that maintain authenticated sessions.
  • Any other data the browser makes available to extensions with elevated privileges. The stolen information is then transmitted to command‑and‑control servers controlled by the threat actors. No CVE identifiers were disclosed, indicating the toolkit may be leveraging existing, documented extension‑install mechanisms rather than a zero‑day vulnerability.

Who Is Affected

The immediate victims are users of Google Chrome and Microsoft Edge who receive the forced extension install. Because both browsers dominate the consumer and enterprise markets, the potential victim pool is extensive. Organizations that allow employees to browse the web with these browsers are at risk, especially if they do not enforce strict extension whitelisting policies. Financial institutions should be particularly concerned, as the stolen credentials can be used to access customer accounts directly.

Why It Matters

Credential and session‑token theft bypasses multi‑factor authentication that relies on the possession of a valid session. Once attackers obtain a live session token, they can act as the legitimate user without triggering additional authentication steps. This capability undermines traditional security controls and accelerates the timeline from compromise to monetary loss. Moreover, the use of a toolkit that automates extension installation demonstrates a scalable approach that can be repurposed for other malicious objectives.

Recommended Actions

  • Enforce Extension Whitelisting: Configure Chrome and Edge policies to allow only approved extensions. Block all unsigned or unknown add‑ons.
  • Monitor Extension Install Events: Deploy endpoint detection and response (EDR) solutions that flag sudden extension installations, especially those originating from non‑administrative processes.
  • Restrict Browser Privileges: Apply least‑privilege principles to browser processes. Prevent standard users from installing extensions without administrator approval.
  • Conduct Credential Hygiene Audits: Encourage users to change passwords regularly and to review active sessions in banking portals. Implement session‑revocation mechanisms where possible.
  • Educate End‑Users: Inform staff and customers about the risk of unsolicited browser extensions and the signs of credential theft.
  • Update Security Tooling: Ensure web‑gateway and proxy solutions can inspect extension traffic and block known malicious payloads.

Conclusion

The KREMLIN‑driven operation illustrates how threat actors can weaponize legitimate browser features to harvest high‑value credentials. By forcing the installation of malicious Chrome and Edge extensions, the campaign sidesteps many traditional defenses and directly targets the data most valuable to financial fraud. Organizations must tighten extension controls, monitor for anomalous install activity, and reinforce credential security to mitigate this emerging threat.

Sources

  • BleepingComputer: https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
#Malware #Browser Security #Credential Theft #Banking Threats #Extension Hijacking
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Vulnerabilities
28 Sep 2026 5 min read

Citrix NetScaler ADC & Gateway Critical RCE Vulnerabilities Actively Exploited

Citrix disclosed two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway that are being exploited in the wild. Patches have been released, but one vulnerability affects every deployment, including default configurations.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

CISA Flags Actively Exploited SharePoint Flaw (CVE‑2026‑65660) with Federal Patch Deadline

CISA has added CVE‑2026‑65660 for Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a September 28 patch deadline for federal agencies. Immediate remediation is required.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

Citrix NetScaler Zero‑Day Exploits (CVE‑2026‑88771/88772) Actively Attacked

Citrix disclosed two critical NetScaler remote code execution flaws, CVE‑2026‑88771 and CVE‑2026‑88772, that are currently being exploited. Security updates are available, and administrators are urged to shut down vulnerable appliances immediately.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.