A New Wave of Banking Malware Targets Web Browsers, Stealing Credentials and Session Tokens from Russian Users
In a disturbing revelation that highlights the ongoing threat of cybercrime in Russia, a sophisticated banking malware campaign has been discovered targeting Google Chrome and Microsoft Edge users. Dubbed “KREMLIN” by researchers, this highly advanced threat leverages zero-day vulnerabilities in both browsers to gain unauthorized access to sensitive user information.
The KREMLIN malware is designed to hijack victims’ web browsing sessions, allowing attackers to steal login credentials and session tokens from Russian banking websites. The attackers use these stolen credentials to authenticate themselves on the targeted bank’s website, effectively bypassing standard security measures such as two-factor authentication. This allows them to siphon off funds from compromised accounts with ease.
But how does KREMLIN work its magic? According to researchers, the malware exploits a specific zero-day vulnerability in Chrome and Edge that enables it to inject malicious JavaScript code into the browser’s rendering engine. This injected code is then executed within the context of the targeted banking website, granting the attackers unfettered access to sensitive user information.
The KREMLIN malware campaign is not just limited to individual users; it also poses a significant threat to Russian businesses that use Chrome or Edge for their online banking needs. With an estimated 90% of Russia’s financial transactions conducted online, this malicious campaign could potentially expose thousands of companies and individuals to crippling cyber attacks.
What makes KREMLIN particularly concerning is its ability to adapt and evolve over time. The malware is designed to update itself automatically, ensuring that it remains one step ahead of security researchers and updates to the targeted browsers. This adaptive nature allows KREMLIN to evade detection by traditional security software, making it all but impossible for victims to recover their stolen data.
The discovery of the KREMLIN malware campaign serves as a stark reminder of the ever-present threat of cybercrime in Russia. As the country’s banking sector continues to digitalize, it is imperative that users and businesses alike take proactive steps to protect themselves from such attacks. This includes staying up-to-date with browser security patches, using robust antivirus software, and practicing good password hygiene.
In light of this alarming revelation, we urge all Chrome and Edge users in Russia to exercise extreme caution when accessing online banking services. By taking these simple precautions, you can significantly reduce the risk of falling prey to the KREMLIN malware campaign and protecting your sensitive financial information from being compromised.
Source: The Hacker News — 2026-09-15