Kremlin Malware Toolkit Steals Bank Passwords and Sessions via Chrome Extensions
Hackers have been quietly force-installing malicious Chrome and Edge extensions that steal bank passwords, cookies, and session data without users' approval.
The KREMLIN bank malware toolkit has powered at least seven campaigns since May 2025 that impersonate 12 Brazilian banks, including Banco do Brasil, Caixa, Bradesco, Sicoob, C6 Bank, Inter, BTG, Safra, PagBank, PicPay, Santander, and Mercado Pago.
The infection begins when a user opens a JavaScript file disguised as a bank receipt, invoice, or business document. The malware copies an extension into the browser's profile folders, edits the Secure Preferences file, and regenerates integrity hashes so Chrome and Edge load it as if the user approved it.
Researchers at Elastic Security Labs say KREMLIN uses a rare technique to manually copy the extension into the browser's profile directories and register it in the Secure Preferences file. The extension masks itself as AVSync, performing various actions such as stealing cookies, local storage, and session storage, keylogging text entered into forms, including passwords.