KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

A sophisticated banking malware operation, allegedly linked to Russian hackers, has compromised Chrome and Edge browsers on thousands of computers worldwide. Dubbed “Kremlin”, this malware leverages a novel technique to hijack user credentials and session tokens, allowing attackers to access sensitive financial information.

The Kremlin malware exploits a vulnerability in the way popular web browsers handle cross-domain requests, allowing it to bypass security measures and inject malicious code into legitimate websites. This allows hackers to steal login credentials, session tokens, and other sensitive data from unsuspecting users who visit compromised sites. The malware is specifically designed to target online banking services, making it a significant concern for financial institutions and their customers.

The Kremlin operation’s reach extends far beyond Russia, with infected computers detected in the United States, Europe, and Asia. Experts warn that the malware could be used to launch targeted attacks on high-value targets such as government officials, business leaders, or individuals with access to sensitive financial information. While the exact number of affected users is unknown, cybersecurity firms have reported a significant spike in Kremlin-related activity over the past few weeks.

Researchers note that the Kremlin malware’s success relies on its ability to manipulate browser behavior, essentially turning legitimate websites into unwitting accomplices in the attack. This is achieved through a technique known as “cross-domain privilege escalation”, which allows the malware to inject malicious code into sites visited by infected users. By doing so, attackers can bypass traditional security measures and access sensitive data without being detected.

The Kremlin operation’s sophistication and reach are likely to raise concerns about the potential for nation-state sponsored attacks on critical infrastructure. Experts warn that this type of malware could be used to launch more sophisticated attacks in the future, potentially leading to significant financial losses or even disruptions to essential services. As a result, users are advised to remain vigilant when browsing online banking services and to ensure their browsers and antivirus software are up-to-date.

In light of these findings, cybersecurity experts recommend that individuals take extra precautions when accessing sensitive information online. This includes regularly updating browser extensions and plugins, using strong passwords and enabling two-factor authentication whenever possible. By taking these simple steps, users can reduce their risk of falling victim to sophisticated attacks like the Kremlin malware operation.


Source: The Hacker News — 2026-09-15