KREMLIN Banking Malware Spreads via Malicious Chrome Extension
Key Takeaways The KREMLIN banking malware campaign employs malicious browser extensions to steal sensitive user data, including passwords and session cookies. The primary targets are users in Brazil,...
Key Takeaways
- The KREMLIN banking malware campaign employs malicious browser extensions to steal sensitive user data, including passwords and session cookies.
- The primary targets are users in Brazil, with over 1,500 infected systems identified across seven campaigns spanning 15 months.
- Attackers use fake JavaScript documents, disguised as bank records or invoices, written in Portuguese to lure victims.
- The malware bypasses official browser stores to install extensions in Chrome and Edge, making detection challenging.
- Mitigation requires vigilance against suspicious email attachments, regular browser extension reviews, and prompt incident response.
Malicious Chrome Extension Spreads KREMLIN Banking Malware
A sophisticated banking malware operation, dubbed KREMLIN, is actively deploying a hostile browser extension on compromised systems. This extension serves as a potent tool for cybercriminals, enabling them to illicitly harvest critical information such as passwords, session cookies, and other data vital for unauthorized access to online accounts.
Table Of Content
Infection Chain and Targeting
The KREMLIN campaign initiates its attack with deceptive JavaScript documents. These files are meticulously crafted to appear as legitimate bank records or invoices. Upon execution, they proceed to install various malicious components, specifically targeting user profiles within Google Chrome and Microsoft Edge browsers.
The lures are strategically written in Portuguese, impersonating prominent Brazilian banks and payment services. Over the past 15 months, researchers have documented seven distinct campaigns, identifying 1,515 infected systems. A staggering 98.75% of these infections were concentrated in Brazil, underscoring the geographical focus of this threat. According to Elastic in a report, their intervention by taking control of a network canary temporarily halted further infections in one instance.
Despite its name, KREMLIN has no discernible connection to Russian operations. The research indicates a clear focus on Brazil, based on the language used in the decoys, the themes of the banking lures, and the observed patterns of malicious activity.
The danger posed by KREMLIN stems from its effective combination of classic social engineering tactics with deep browser-level access. This approach allows the malware to circumvent the inherent caution users typically exercise when encountering suspicious login pages, as the malicious activity occurs within what appears to be a legitimate browser environment.
KREMLIN Banking Malware Infects Over 1,500 Systems
Once a victim activates the initial lure, KREMLIN employs a multi-stage process to evade detection and install its components. This includes checks for sandbox environments, creation of a scheduled task for persistence, and retrieval of current hosting details from an Ethereum smart contract. This innovative use of blockchain technology allows the operators to rapidly change their infrastructure without needing to recompile and redistribute new malware samples.
The installer then covertly copies the malicious extension directly into Chrome and Edge profile folders, completely bypassing the official browser extension stores. It meticulously modifies Chrome’s protected preferences and replicates the internal checks that typically validate extension settings. This manipulation tricks the browser into recognizing the rogue add-on as legitimate, despite the user never having manually installed it.
The malicious extension, often posing as “AVSync,” requests extensive permissions, including access to tabs, cookies, browser storage, and network requests. With these privileges, it can capture screenshots, enumerate open browser tabs, exfiltrate cookies and stored web data, log keystrokes, and inject attacker-controlled content directly into web pages. This method highlights why browser add-ons have become a highly attractive vector for cybercriminals seeking banking credentials in Brazil and beyond.
Furthermore, the malware archives browser databases and encryption keys before transmitting this sensitive data to remote servers. The theft of a valid session cookie can enable an attacker to reuse an authenticated account, gaining access without needing the user’s password. This attack vector mirrors broader trends in malicious Chrome extension campaigns, where extensive browser permissions are abused for data exfiltration.
Banking Lures and Response
The KREMLIN operators have continuously refined their toolkit since May 2025. Earlier campaigns often deployed other remote access tools alongside the malicious extensions. More recent activity has incorporated blockchain-hosted configuration and leveraged a signed security program component to load an unsigned malicious file. The shared infrastructure across these variations suggests a coordinated effort in managing the infection chain. The latest wave of attacks specifically targets Brazilian users with filenames designed to mimic receipts, payment records, bank statements, and instant payment documents.
A fake error message is often used to mask the infection process. This combination of convincing document lures and silent installation transforms routine file-opening habits into significant security risks. Organizations must educate their staff that legitimate banks and payment providers do not typically send JavaScript files as documents. It is crucial to implement policies to block script files received via email or messaging platforms where feasible, regularly inspect scheduled tasks and browser profiles for unauthorized modifications, and actively hunt for indicators of compromise.
Teams responding to a suspected KREMLIN infection should immediately isolate the affected device, remove the malicious extension, reset all compromised passwords from a clean system, and revoke active sessions. Users are advised to review every installed browser extension, removing any unfamiliar entries, particularly those requesting broad access to websites, cookies, or tabs. Always use official banking applications or access banking websites via bookmarks, rather than clicking links from messages. This advice aligns with best practices for incidents involving stolen passwords and sessions, where prompt credential changes and session revocation from a secure device are paramount. While the temporary disruption caused by the canary takeover provided a brief respite, it does not guarantee the complete eradication of the threat. Given KREMLIN’s use of dynamic online configurations, defenders must prioritize behavioral monitoring in addition to blocking known infrastructure. Proactive browser reviews, robust email filtering, endpoint monitoring, and swift session revocation are essential measures to limit potential damage.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 |
KREMLIN JavaScript loader sample |
| SHA-256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 |
First-stage popup JavaScript sample |
| SHA-256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 |
KREMLIN x64 extension installer binary |
| SHA-256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca |
Malicious AVSync extension sample |
| SHA-256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f |
Related Wave A loader sample |
| SHA-256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 |
Related Wave B loader sample |
| SHA-256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c |
Related Wave C loader sample |
| SHA-256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 |
PowerShell extension-installer implementation |
| Domain | connection[.]upgradeonline[.]site |
Loader beaconing and extension-delivery infrastructure |
| Domain | www[.]creamp1eonlyfans[.]net |
Network canary domain checked by KREMLIN |
| Domain | granderevolucao[.]store |
Installer payload-hosting domain |
| Domain | volmira[.]site |
Extension hosting and credential-exfiltration infrastructure |
| Domain | zaviro[.]online |
Exfiltration and fingerprinting infrastructure |
| Domain | graph[.]checkeligibitily[.]workers[.]dev |
Extension endpoint resolver |
| Domain | luizestrelhashapr[.]online |
Resolved WebSocket command-and-control host |
| Domain | seguranca[.]versionnova[.]site |
Infrastructure associated with a related KREMLIN branch |
| Domain | codecaudiog[.]site |
Earlier KREMLIN campaign staging domain |
| Domain | codecvideowin[.]online |
Earlier campaign extension-hosting domain |
| Domain | acrobat-updater[.]com |
Earlier campaign lure and payload-hosting domain |
| Domain | lojinhadoluiz[.]online |
FrameSync campaign extension infrastructure |
| Domain | orange-sun-195a[.]checkeligibitily[.]workers[.]dev |
FrameSync campaign C2 resolver |
| Domain | cremeb[.]com |
QR-extension and earlier KREMLIN campaign infrastructure |
| Domain | donalurdesconfeitos[.]site |
Earlier extension-delivery infrastructure |
| Domain | marialurdes[.]site |
Intermediate KREMLIN campaign domain |
| Domain | harialurdes[.]site |
Intermediate KREMLIN campaign domain |
| IP address | 178.92.162[.]38:443 |
REMCOS RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:4782 |
Earlier PULSAR RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:443 |
Earlier PULSAR RAT command-and-control endpoint |
| IP address | 144.172.112[.]239:4782 |
Acrobat campaign PULSAR RAT endpoint |
| IP address | 45.90.13[.]210:443 |
Acrobat campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]100:443 |
Cremeb campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]34:443 |
Cremeb campaign PULSAR RAT endpoint |
| Ethereum smart contract | 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b |
Active KREMLIN configuration dead-drop resolver |
| Chrome extension ID | ndpbidppejfanjbhfgjlohfanbfbklff |
AVSync malicious extension ID |
| Chrome extension ID | djodclnjknbpambeaaapadmdfhmbpeog |
FrameSync malicious extension ID |
| Chrome extension ID | cdgcjghdeinagopbaobhmaefigoafaaa |
QR-themed malicious extension ID |
| File name | SentinelMemoryScanner.exe |
Signed binary abused for DLL side-loading |
| File name | SentinelAgentCore.dll |
Unsigned KREMLIN payload masquerading as a legitimate DLL |
| File name | MicrosoftNodeRuntimeUpdater |
Scheduled-task name used for persistence |
| File name | output_image_202505.jpg |
Earlier Internet Archive-hosted RunPE module |
| File name | hotelmoskva.jpg |
JPEG carrier used to conceal a .NET injector |
| File name | tragira.jpg |
JPEG carrier used in the Acrobat campaign |
| Mutex | ClarinhoQueSim-XEDA2O |
KREMLIN campaign mutex |
| Customer ID | 98d8049e-804f-11f1-b79f-ae3a8bb85d01 |
Identifier associated with the current campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Educate Users: Inform staff and users that legitimate banks and payment services do not typically send JavaScript files as attachments. Emphasize caution with all unexpected email attachments.
- Block Script Files: Configure email and messaging filters to block incoming script files (e.g.,
.js,.jse) whenever possible. - Review Browser Extensions: Regularly audit installed browser extensions in Chrome and Edge. Remove any unfamiliar or suspicious extensions, especially those with broad permissions.
- Inspect Scheduled Tasks: Periodically check scheduled tasks on endpoints for unauthorized or suspicious entries that could indicate persistence mechanisms.
- Monitor Browser Profiles: Implement endpoint detection and response (EDR) solutions to monitor changes to browser profile folders and settings that might indicate unauthorized extension installation.
- Reset Credentials and Sessions: In case of a suspected infection, immediately isolate the affected device, remove the malicious extension, reset all affected passwords from a clean, trusted system, and revoke all active sessions for compromised accounts.
- Use Official Channels: Always access banking and payment services through official mobile applications or by typing the URL directly into the browser or using trusted bookmarks, rather than clicking links from emails or messages.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.