Malware bypasses browser checks to force install Chrome, Edge extensions

Summary

A banking malware operation has been using a toolkit called KREMLIN since mid-2025 to install malicious Chrome and Edge extensions. These extensions are designed to steal credentials, session tokens, and other sensitive data from users.

IFF Assessment

FOE

This article details a new malware technique that actively steals sensitive user data, posing a direct threat to individuals and organizations.

Defender Context

This highlights a sophisticated malware campaign that bypasses typical browser security measures to install malicious extensions. Defenders should be aware of this technique and educate users about the risks of installing extensions from untrusted sources, and ensure endpoint protection solutions are up-to-date to detect such threats.

Read Full Story →