Malware bypasses browser checks to force install Chrome, Edge extensions

Malicious Browser Extensions Spreading in Brazil, Stealing Sensitive Data

A sophisticated malware operation has been spreading in Brazil since mid-2025, using a toolkit called KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. Researchers at Elastic Security Labs discovered the campaign and have now disrupted it by registering a domain used as an anti-sandbox canary.

The malware infects users after they open a JavaScript file disguised as a bank receipt, invoice, payment record, or business document. Once inside, KREMLIN bypasses browser checks to force install extensions on Chrome and Edge browsers without user approval. The malicious code uses encryption keys the browser employs to protect sensitive data, recreating integrity checks to make the extension appear valid.

The installed extensions, masquerading as AVSync, perform a range of malicious actions, including stealing cookies, local storage, and session storage, keylogging text entered into forms, capturing screenshots and page source, enumerating open tabs and browsing history, intercepting HTTP request bodies and headers, injecting attacker-controlled HTML into websites, redirecting clicks to attacker-selected destinations, and receiving commands through a WebSocket connection. In addition to the extension, KREMLIN also acts as an info-stealer that can archive and exfiltrate browser databases, cookies, installed extensions, and App-Bound cryptographic keys.

The malware’s tactics are sophisticated, using Ethereum smart contracts as dead-drop resolvers and abusing the Internet Archive service to host payloads hidden inside JPEG images. The researchers found a connection between the malware campaigns and a Brazilian operation responsible for at least seven campaigns since May 2025 that used lures impersonating 12 banks. The wallet handling the operations handled roughly 20,800 USDT (Tether) in incoming transfers and 19,000 USDT in outgoing transfers.

Elastic Security Labs has confirmed 1,515 infected systems, almost all located in Brazil. The security firm disrupted the current KREMLIN campaign by registering a domain used as an anti-sandbox canary, causing the loader to stop due to false flags on systems that would otherwise qualify for infection.

The tactics and techniques used in KREMLIN attacks have been shared by Elastic Security Labs researchers, along with indicators of compromise. This information is crucial for anyone concerned about the security of their browser extensions and the potential risks associated with them.

To protect yourself from similar malware operations, it’s essential to be cautious when opening attachments or links from unknown sources, especially those related to financial transactions or business documents. Regularly updating your browser and its extensions is also vital to prevent malicious actors from exploiting vulnerabilities in outdated software. Additionally, consider enabling two-factor authentication on all sensitive accounts to add an extra layer of security against unauthorized access.

By staying informed about emerging threats and taking proactive measures to protect yourself, you can significantly reduce the risk of falling victim to sophisticated malware operations like KREMLIN.


Source: Bleeping Computer — 2026-09-16