Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Von der Leyen fleshes out Carney’s vision to paint Europe as leader of world’s middle powers – POLITICO

    September 16, 2026

    Nato leader warns of ‘most dangerous and complex security environment in a generation’ | World news

    September 16, 2026

    ‘Made in Europe’ laws could derail UK plans for reset with EU | European Union

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Von der Leyen fleshes out Carney’s vision to paint Europe as leader of world’s middle powers – POLITICO
    • Nato leader warns of ‘most dangerous and complex security environment in a generation’ | World news
    • ‘Made in Europe’ laws could derail UK plans for reset with EU | European Union
    • A Deal Hunter’s Guide to Amazon Prime Big Deal Days (2026)
    • Malware bypasses browser checks to force install Chrome, Edge extensions
    • Live updates: Bitcoin slips as Fed hikes rates and suggests more to come
    • These mice have human (nerve cells) on the brain
    • FSRU docks in Stade as LNG terminal prepares to feed gas into German grid from November
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Malware bypasses browser checks to force install Chrome, Edge extensions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.

    Researchers at Elastic Security Labs found that the malicious extensions bypass Chromium’s integrity mechanisms and load in browsers as if they had been approved by the user.

    The infection chain starts after the target user opens a JavaScript file disguised as a bank receipt, invoice, payment record, or business document.

    After passing anti-sandbox checks, the file triggers a fake error while simultaneously downloading Node.js, establishing persistence through a scheduled task, and retrieving the additional payload location from an Ethereum smart contract.

    Despite the name, KREMLIN is linked to a Brazilian operation responsible for at least seven campaigns since May 2025 that use lures impersonating 12 banks.

    Installing Chrome and Edge add-ons

    A standout feature of KREMLIN is its capability to install extensions on Chrome and Edge browsers without asking the user to approve them.

    It waits for the browser to close or terminates it when it detects idle status, and then copies the extension into the app’s profile directories. Next, it enables developer mode and adds the extension to Chromium’s Secure Preferences.

    To hide its activity, the malware uses the encryption keys the browser uses to protect sensitive data and then recreates the integrity checks Chrome uses to detect changes in browser preferences.

    This makes the malicious extension appear valid to the browser despite never being approved by the user, a documented but rarely used technique according to the researchers.

    “KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser’s profile directories and registers it in the Secure Preferences file,” Elastic explains.

    “Because Chromium protects these entries with cryptographic integrity checks, the malware must retrieve the required keys and regenerate the associated HMACs and encrypted hashes.”

    Once installed, the extension masquerades as AVSync and performs the following actions:

    • Steals cookies, local storage, and session storage
    • Keylogs text entered into forms, including passwords
    • Captures screenshots and page source
    • Enumerates open tabs and browsing history
    • Intercepts HTTP request bodies and headers
    • Injects attacker-controlled HTML into websites
    • Redirects clicks to attacker-selected destinations
    • Receives commands through a WebSocket connection

    Apart from the malicious extension, the KREMLIN toolkit also acts as an info-stealer that can archive and exfiltrate browser databases, cookies, installed extensions, and the App-Bound cryptographic keys needed to decrypt protected data.

    Overview of the REF9334 attack chain
    Overview of the REF9334 attack chain
    Source: Elastic

    Disrupting the operation

    Elastic Security Labs researchers found that KREMLIN malware campaigns use Ethereum smart contracts as dead-drop resolvers and also abuse the Internet Archive service to host payloads hidden inside JPEG images.

    In more recent campaigns, the threat actor deployed the REMCOS remote access tool, but past operations pushed the Pulsar RAT. According to the researchers, the switch was likely due to REMCOS being more feature rich.

    By connecting the dots through infrastructure analysis and code artifacts, the researchers found the Ethereum wallet that deployed and updated the smart contracts

    According to the researchers, the wallet handled roughly 20,800 USDT (Tether) and 19,000 USDT in incoming and outgoing transfers, respectively. Elastic has confirmed 1,515 infected systems, almost all located in Brazil.

    The security firm disrupted the current KREMLIN campaign by registering a domain that the malware used as an anti-sandbox canary, causing the loader to stop due to false flags on systems that would otherwise qualify for infection.

    Elastic Security Labs researchers shared the tactics and techniques used in KREMLIN attacks, as well as a set of indicators of compromise.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    browser bypasses checks Chrome Edge extensions force install Malware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

    Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    Hack-back programs could expose your security vendors

    The true cost of a ransomware attack, with and without BCDR

    N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Von der Leyen fleshes out Carney’s vision to paint Europe as leader of world’s middle powers – POLITICO

    September 16, 2026

    Nato leader warns of ‘most dangerous and complex security environment in a generation’ | World news

    September 16, 2026

    ‘Made in Europe’ laws could derail UK plans for reset with EU | European Union

    September 16, 2026

    A Deal Hunter’s Guide to Amazon Prime Big Deal Days (2026)

    September 16, 2026
    Latest Posts

    What is Trump Media’s Truth API and why is it controversial?

    August 4, 2026

    How ProPublica Tested Hundreds of Omaha Homes for Lead — ProPublica

    August 4, 2026

    Golar LNG raises $600 million loan with FLNG business expansion in mind

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Von der Leyen fleshes out Carney’s vision to paint Europe as leader of world’s middle powers – POLITICO

    September 16, 2026

    Nato leader warns of ‘most dangerous and complex security environment in a generation’ | World news

    September 16, 2026

    ‘Made in Europe’ laws could derail UK plans for reset with EU | European Union

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.