Malware bypasses browser checks to force install Chrome, Edge extensions

Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware campaign active since mid-2025 has used the KREMLIN toolkit to silently install malicious Chrome and Edge extensions that steal credentials, session tokens, and browser data. Elastic Security Labs linked the operation to a Brazilian threat actor, confirmed 1,515 infected systems, and disrupted part of the campaign by registering a key anti-sandbox domain. #KREMLIN #ElasticSecurityLabs #REMCOS #PulsarRAT #Brazil

Keypoints

  • KREMLIN installs malicious Chrome and Edge extensions without user approval.
  • The infection begins with a fake JavaScript document posing as a bank-related file.
  • The malware uses anti-sandbox checks, scheduled tasks, and Ethereum smart contracts.
  • The extension steals cookies, tokens, passwords, screenshots, and browser activity.
  • Elastic linked the campaign to Brazil and confirmed 1,515 infected systems.

Read More: https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/