Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Parallels Desktop Vulnerability Lets Non-Admin Mac Users Execute Code as Root
September 16, 2026
Critical Acronis Cyber Protection Vulnerability in cPanel, Plesk Exploosed
September 16, 2026
KREMLIN Banking Malware Spreads via Malicious Chrome Extension
September 16, 2026
Home/CyberSecurity News/KREMLIN Banking Malware Spreads via Malicious Chrome Extension
CyberSecurity News

KREMLIN Banking Malware Spreads via Malicious Chrome Extension

Key Takeaways The KREMLIN banking malware campaign employs malicious browser extensions to steal sensitive user data, including passwords and session cookies. The primary targets are users in Brazil,...

Sarah simpson
Sarah simpson
September 16, 2026 6 Min Read
3 0

Key Takeaways

  • The KREMLIN banking malware campaign employs malicious browser extensions to steal sensitive user data, including passwords and session cookies.
  • The primary targets are users in Brazil, with over 1,500 infected systems identified across seven campaigns spanning 15 months.
  • Attackers use fake JavaScript documents, disguised as bank records or invoices, written in Portuguese to lure victims.
  • The malware bypasses official browser stores to install extensions in Chrome and Edge, making detection challenging.
  • Mitigation requires vigilance against suspicious email attachments, regular browser extension reviews, and prompt incident response.

Malicious Chrome Extension Spreads KREMLIN Banking Malware

A sophisticated banking malware operation, dubbed KREMLIN, is actively deploying a hostile browser extension on compromised systems. This extension serves as a potent tool for cybercriminals, enabling them to illicitly harvest critical information such as passwords, session cookies, and other data vital for unauthorized access to online accounts.

Table Of Content

  • Key Takeaways
  • Malicious Chrome Extension Spreads KREMLIN Banking Malware
  • Infection Chain and Targeting
  • KREMLIN Banking Malware Infects Over 1,500 Systems
  • Banking Lures and Response
  • Indicators of Compromise (IoCs)
  • What You Should Do

Infection Chain and Targeting

The KREMLIN campaign initiates its attack with deceptive JavaScript documents. These files are meticulously crafted to appear as legitimate bank records or invoices. Upon execution, they proceed to install various malicious components, specifically targeting user profiles within Google Chrome and Microsoft Edge browsers.

The lures are strategically written in Portuguese, impersonating prominent Brazilian banks and payment services. Over the past 15 months, researchers have documented seven distinct campaigns, identifying 1,515 infected systems. A staggering 98.75% of these infections were concentrated in Brazil, underscoring the geographical focus of this threat. According to Elastic in a report, their intervention by taking control of a network canary temporarily halted further infections in one instance.

Despite its name, KREMLIN has no discernible connection to Russian operations. The research indicates a clear focus on Brazil, based on the language used in the decoys, the themes of the banking lures, and the observed patterns of malicious activity.

The danger posed by KREMLIN stems from its effective combination of classic social engineering tactics with deep browser-level access. This approach allows the malware to circumvent the inherent caution users typically exercise when encountering suspicious login pages, as the malicious activity occurs within what appears to be a legitimate browser environment.

KREMLIN Banking Malware Infects Over 1,500 Systems

Once a victim activates the initial lure, KREMLIN employs a multi-stage process to evade detection and install its components. This includes checks for sandbox environments, creation of a scheduled task for persistence, and retrieval of current hosting details from an Ethereum smart contract. This innovative use of blockchain technology allows the operators to rapidly change their infrastructure without needing to recompile and redistribute new malware samples.

The installer then covertly copies the malicious extension directly into Chrome and Edge profile folders, completely bypassing the official browser extension stores. It meticulously modifies Chrome’s protected preferences and replicates the internal checks that typically validate extension settings. This manipulation tricks the browser into recognizing the rogue add-on as legitimate, despite the user never having manually installed it.

The malicious extension, often posing as “AVSync,” requests extensive permissions, including access to tabs, cookies, browser storage, and network requests. With these privileges, it can capture screenshots, enumerate open browser tabs, exfiltrate cookies and stored web data, log keystrokes, and inject attacker-controlled content directly into web pages. This method highlights why browser add-ons have become a highly attractive vector for cybercriminals seeking banking credentials in Brazil and beyond.

Furthermore, the malware archives browser databases and encryption keys before transmitting this sensitive data to remote servers. The theft of a valid session cookie can enable an attacker to reuse an authenticated account, gaining access without needing the user’s password. This attack vector mirrors broader trends in malicious Chrome extension campaigns, where extensive browser permissions are abused for data exfiltration.

Banking Lures and Response

The KREMLIN operators have continuously refined their toolkit since May 2025. Earlier campaigns often deployed other remote access tools alongside the malicious extensions. More recent activity has incorporated blockchain-hosted configuration and leveraged a signed security program component to load an unsigned malicious file. The shared infrastructure across these variations suggests a coordinated effort in managing the infection chain. The latest wave of attacks specifically targets Brazilian users with filenames designed to mimic receipts, payment records, bank statements, and instant payment documents.

A fake error message is often used to mask the infection process. This combination of convincing document lures and silent installation transforms routine file-opening habits into significant security risks. Organizations must educate their staff that legitimate banks and payment providers do not typically send JavaScript files as documents. It is crucial to implement policies to block script files received via email or messaging platforms where feasible, regularly inspect scheduled tasks and browser profiles for unauthorized modifications, and actively hunt for indicators of compromise.

Teams responding to a suspected KREMLIN infection should immediately isolate the affected device, remove the malicious extension, reset all compromised passwords from a clean system, and revoke active sessions. Users are advised to review every installed browser extension, removing any unfamiliar entries, particularly those requesting broad access to websites, cookies, or tabs. Always use official banking applications or access banking websites via bookmarks, rather than clicking links from messages. This advice aligns with best practices for incidents involving stolen passwords and sessions, where prompt credential changes and session revocation from a secure device are paramount. While the temporary disruption caused by the canary takeover provided a brief respite, it does not guarantee the complete eradication of the threat. Given KREMLIN’s use of dynamic online configurations, defenders must prioritize behavioral monitoring in addition to blocking known infrastructure. Proactive browser reviews, robust email filtering, endpoint monitoring, and swift session revocation are essential measures to limit potential damage.

Indicators of Compromise (IoCs)

Type Indicator Description
SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample
SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample
SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary
SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample
SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample
SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample
SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample
SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation
Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure
Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN
Domain granderevolucao[.]store Installer payload-hosting domain
Domain volmira[.]site Extension hosting and credential-exfiltration infrastructure
Domain zaviro[.]online Exfiltration and fingerprinting infrastructure
Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver
Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host
Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch
Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain
Domain codecvideowin[.]online Earlier campaign extension-hosting domain
Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain
Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure
Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver
Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure
Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure
Domain marialurdes[.]site Intermediate KREMLIN campaign domain
Domain harialurdes[.]site Intermediate KREMLIN campaign domain
IP address 178.92.162[.]38:443 REMCOS RAT command-and-control endpoint
IP address 185.221.23[.]133:4782 Earlier PULSAR RAT command-and-control endpoint
IP address 185.221.23[.]133:443 Earlier PULSAR RAT command-and-control endpoint
IP address 144.172.112[.]239:4782 Acrobat campaign PULSAR RAT endpoint
IP address 45.90.13[.]210:443 Acrobat campaign PULSAR RAT endpoint
IP address 37.16.74[.]100:443 Cremeb campaign PULSAR RAT endpoint
IP address 37.16.74[.]34:443 Cremeb campaign PULSAR RAT endpoint
Ethereum smart contract 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b Active KREMLIN configuration dead-drop resolver
Chrome extension ID ndpbidppejfanjbhfgjlohfanbfbklff AVSync malicious extension ID
Chrome extension ID djodclnjknbpambeaaapadmdfhmbpeog FrameSync malicious extension ID
Chrome extension ID cdgcjghdeinagopbaobhmaefigoafaaa QR-themed malicious extension ID
File name SentinelMemoryScanner.exe Signed binary abused for DLL side-loading
File name SentinelAgentCore.dll Unsigned KREMLIN payload masquerading as a legitimate DLL
File name MicrosoftNodeRuntimeUpdater Scheduled-task name used for persistence
File name output_image_202505.jpg Earlier Internet Archive-hosted RunPE module
File name hotelmoskva.jpg JPEG carrier used to conceal a .NET injector
File name tragira.jpg JPEG carrier used in the Acrobat campaign
Mutex ClarinhoQueSim-XEDA2O KREMLIN campaign mutex
Customer ID 98d8049e-804f-11f1-b79f-ae3a8bb85d01 Identifier associated with the current campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Educate Users: Inform staff and users that legitimate banks and payment services do not typically send JavaScript files as attachments. Emphasize caution with all unexpected email attachments.
  • Block Script Files: Configure email and messaging filters to block incoming script files (e.g., .js, .jse) whenever possible.
  • Review Browser Extensions: Regularly audit installed browser extensions in Chrome and Edge. Remove any unfamiliar or suspicious extensions, especially those with broad permissions.
  • Inspect Scheduled Tasks: Periodically check scheduled tasks on endpoints for unauthorized or suspicious entries that could indicate persistence mechanisms.
  • Monitor Browser Profiles: Implement endpoint detection and response (EDR) solutions to monitor changes to browser profile folders and settings that might indicate unauthorized extension installation.
  • Reset Credentials and Sessions: In case of a suspected infection, immediately isolate the affected device, remove the malicious extension, reset all affected passwords from a clean, trusted system, and revoke all active sessions for compromised accounts.
  • Use Official Channels: Always access banking and payment services through official mobile applications or by typing the URL directly into the browser or using trusted bookmarks, rather than clicking links from emails or messages.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Iranian Hackers Deploy CHOSEN BRICK Spyware via Fake MRI Results

Next Post

Critical Acronis Cyber Protection Vulnerability in cPanel, Plesk Exploosed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best SaaS Security Posture Management (SSPM) Tools
September 16, 2026
Top 10 Cloud Detection and Response Solutions for 2026
September 16, 2026
Microsoft Patches Critical Windows 11 Vulnerability CVE-2023-XXXXX
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us