Malware bypasses browser checks to force install Chrome, Edge extensions
Summary
A banking malware operation has been using a toolkit called KREMLIN since mid-2025 to install malicious Chrome and Edge extensions. These extensions are designed to steal credentials, session tokens, and other sensitive data from users.
IFF Assessment
FOE
This article details a new malware technique that actively steals sensitive user data, posing a direct threat to individuals and organizations.
Defender Context
This highlights a sophisticated malware campaign that bypasses typical browser security measures to install malicious extensions. Defenders should be aware of this technique and educate users about the risks of installing extensions from untrusted sources, and ensure endpoint protection solutions are up-to-date to detect such threats.