Malware bypasses browser checks to force install Chrome, Edge extensions

Malicious extension operation spreads in Brazil, infects over 1,500 systems

A sophisticated malware campaign has been making headlines in recent months, with researchers at Elastic Security Labs uncovering a toolkit named KREMLIN that’s being used to install malicious Chrome and Edge extensions. These extensions are designed to steal sensitive information from unsuspecting users, including credentials, session tokens, and even screenshots of their browsing activity.

The operation, which has been active since mid-2025, targets victims in Brazil, with over 1,500 systems already infected. The malware uses a variety of techniques to evade detection, including anti-sandbox checks and the use of Ethereum smart contracts as dead-drop resolvers. Once installed, the malicious extension masquerades as AVSync and performs a range of nefarious actions, from keylogging passwords to injecting attacker-controlled HTML into websites.

But what’s particularly concerning about this operation is its ability to bypass browser checks and install extensions without user approval. By manually copying the extension into the browser’s profile directories and registering it in the Secure Preferences file, KREMLIN effectively “fools” the browser into thinking the extension was installed by the user themselves. This technique is rarely observed in malware, making it all the more sophisticated.

The infection chain starts with a JavaScript file disguised as a bank receipt or invoice, which is designed to look convincing enough to fool even the most vigilant users. Once opened, the file triggers a fake error while simultaneously downloading Node.js and establishing persistence through a scheduled task. The additional payload location is then retrieved from an Ethereum smart contract, allowing the malware to download and install further components.

One of the most striking aspects of KREMLIN is its use of encryption keys to protect sensitive data – a technique that’s typically used by legitimate browser vendors to ensure user security. By using these same techniques against the user, the malware effectively “re-encrypts” itself, making it appear as though the malicious extension was installed by the user themselves.

The good news is that Elastic Security Labs has disrupted the current KREMLIN campaign, registering a domain that the malware uses as an anti-sandbox canary. This has prevented further infections and provided researchers with valuable insights into the operation’s tactics and techniques.

So what can we learn from this operation? Firstly, it highlights the importance of staying vigilant when opening email attachments or clicking on links – no matter how convincing they may seem. Secondly, it underscores the need for robust browser security measures, including regular updates and patches to prevent exactly this kind of attack.

Ultimately, this campaign serves as a reminder that cyber threats are constantly evolving, and that even the most sophisticated malware can evade detection if not properly equipped. As we move forward in this digital age, it’s more crucial than ever to stay informed about emerging threats and take proactive steps to protect ourselves from the next big attack.

In practical terms, users should be extremely cautious when downloading software or extensions from untrusted sources – always checking reviews and ratings before installing anything new. Regularly updating browsers and plugins is also essential, as well as using reputable antivirus software to scan for malware. By taking these simple precautions, we can significantly reduce our exposure to threats like KREMLIN and stay one step ahead of cybercriminals.


Source: Bleeping Computer — 2026-09-16