KREMLIN toolkit exploits Chromium integrity to silently inject credential-stealing extensions

A banking malware operation active since mid-2025 uses a toolkit named KREMLIN to install malicious Chrome and Edge extensions without user consent. The malware copies extensions into browser profile directories and manipulates Chromium's integrity mechanisms to make them appear legitimate. These extensions steal credentials, session tokens, and other sensitive data, with lures impersonating banks and business documents.
The toolkit's operation begins with a JavaScript file disguised as financial documents, which triggers a fake error while quietly installing Node.js and establishing persistence through scheduled tasks. Command locations are retrieved via Ethereum smart contracts, with the associated wallet moving roughly 20,800 USDT in incoming transfers. Elastic researchers disrupted one campaign by registering a domain used as an anti-sandbox canary, halting the loader.
The malicious extension, masquerading as AVSync, captures cookies, logs keystrokes, screenshots pages, and intercepts HTTP traffic. Beyond extensions, KREMLIN functions as an info-stealer, exfiltrating browser databases and App-Bound cryptographic keys. Recent campaigns shifted from Pulsar RAT to REMCOS, likely for its richer feature set. Elastic confirmed 1,515 infected systems, nearly all in Brazil.
This campaign could most directly affect banking customers in Brazil, as lures impersonate twelve banks and nearly all confirmed infections are there. The technique of bypassing Chromium's integrity checks may raise concerns about browser security assumptions, potentially prompting vendors to strengthen extension verification. Businesses receiving fraudulent invoices or payment documents could face credential theft and financial loss. The use of Ethereum smart contracts and Internet Archive hosting suggests attackers are adapting to resilient infrastructure, which may complicate takedown efforts.