Banking Malware Employs ‘KREMLIN’ Toolkit to Covertly Install Malicious Chrome and Edge Extensions
A newly identified banking‑focused malware campaign has begun deploying a custom toolkit called KREMLIN to force‑install hostile extensions for Google Chrome and Microsoft Edge, allowing attackers to harvest login credentials, session tokens and other sensitive information from victims.
Security researchers first observed the operation in mid‑2025, noting that the malicious code bypasses standard browser safeguards that normally block unsigned or unapproved add‑ons. The findings were originally disclosed by BleepingComputer after analysts traced the payload to a network of compromised machines used to distribute the toolkit.
KREMLIN works by exploiting a combination of browser‑level APIs and social‑engineering tricks that convince the browser to accept the extension without displaying the usual permission prompts. In many cases, the malicious add‑on is silently added to the user’s profile after the victim clicks a seemingly innocuous link or opens a compromised document, effectively sidestepping the Chrome Web Store and Edge Add‑ons store vetting processes.
Once installed, the extensions monitor web traffic directed at banking portals, capture entered usernames and passwords, and exfiltrate active session cookies that can be reused to hijack accounts. Researchers say the stolen data is routed to command‑and‑control servers operated by the threat actors, who then monetize the information through fraudulent transactions or by selling credentials on underground markets.
The campaign underscores a growing trend of extension‑based attacks, which have risen as traditional malware delivery methods become more heavily scrutinized. Browsers have introduced stricter review procedures and runtime checks, yet attackers continue to adapt by crafting toolkits like KREMLIN that operate at the edge of those defenses.
Experts advise users to regularly audit installed extensions, remove any that are unfamiliar, and keep browsers up to date with the latest security patches. Financial institutions are urging customers to enable multi‑factor authentication and to monitor account activity for anomalies. Meanwhile, security firms are developing detection signatures for the KREMLIN toolkit, and browser vendors are reportedly reviewing their extension installation flows to close the loopholes exploited by this latest threat.
Comments (0)
Be the first to comment.
Join the discussion