MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-16 · via BleepingComputer

KREMLIN toolkit exploits Chromium integrity to silently inject credential-stealing extensions

Image via BleepingComputer
Image via BleepingComputer

A banking malware operation active since mid-2025 uses a toolkit named KREMLIN to install malicious Chrome and Edge extensions without user consent. The malware copies extensions into browser profile directories and manipulates Chromium's integrity mechanisms to make them appear legitimate. These extensions steal credentials, session tokens, and other sensitive data, with lures impersonating banks and business documents.

Expanded Detail

The toolkit's operation begins with a JavaScript file disguised as financial documents, which triggers a fake error while quietly installing Node.js and establishing persistence through scheduled tasks. Command locations are retrieved via Ethereum smart contracts, with the associated wallet moving roughly 20,800 USDT in incoming transfers. Elastic researchers disrupted one campaign by registering a domain used as an anti-sandbox canary, halting the loader.

The malicious extension, masquerading as AVSync, captures cookies, logs keystrokes, screenshots pages, and intercepts HTTP traffic. Beyond extensions, KREMLIN functions as an info-stealer, exfiltrating browser databases and App-Bound cryptographic keys. Recent campaigns shifted from Pulsar RAT to REMCOS, likely for its richer feature set. Elastic confirmed 1,515 infected systems, nearly all in Brazil.

Context

This campaign could most directly affect banking customers in Brazil, as lures impersonate twelve banks and nearly all confirmed infections are there. The technique of bypassing Chromium's integrity checks may raise concerns about browser security assumptions, potentially prompting vendors to strengthen extension verification. Businesses receiving fraudulent invoices or payment documents could face credential theft and financial loss. The use of Ethereum smart contracts and Internet Archive hosting suggests attackers are adapting to resilient infrastructure, which may complicate takedown efforts.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Malware bypasses browser checks to force install Chrome, Edge extensions.” Browse more stories.