A banking malware campaign active since mid-2025 has used the KREMLIN toolkit to silently install malicious Chrome and Edge extensions that steal credentials, session tokens, and browser data. Elastic Security Labs linked the operation to a Brazilian threat actor, confirmed 1,515 infected systems, and disrupted part of the campaign by registering a key anti-sandbox domain. #KREMLIN #ElasticSecurityLabs #REMCOS #PulsarRAT #Brazil
Keypoints
- KREMLIN installs malicious Chrome and Edge extensions without user approval.
- The infection begins with a fake JavaScript document posing as a bank-related file.
- The malware uses anti-sandbox checks, scheduled tasks, and Ethereum smart contracts.
- The extension steals cookies, tokens, passwords, screenshots, and browser activity.
- Elastic linked the campaign to Brazil and confirmed 1,515 infected systems.