Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Malware bypasses browser checks to force install Chrome, Edge extensions
    News

    Malware bypasses browser checks to force install Chrome, Edge extensions

    adminBy adminSeptember 16, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Malware bypasses browser checks to force install Chrome, Edge extensions

    A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.

    Researchers at Elastic Security Labs found that the malicious extensions bypass Chromium’s integrity mechanisms and load in browsers as if they had been approved by the user.

    The infection chain starts after the target user opens a JavaScript file disguised as a bank receipt, invoice, payment record, or business document.

    After passing anti-sandbox checks, the file triggers a fake error while simultaneously downloading Node.js, establishing persistence through a scheduled task, and retrieving the additional payload location from an Ethereum smart contract.

    Despite the name, KREMLIN is linked to a Brazilian operation responsible for at least seven campaigns since May 2025 that use lures impersonating 12 banks.

    Installing Chrome and Edge add-ons

    A standout feature of KREMLIN is its capability to install extensions on Chrome and Edge browsers without asking the user to approve them.

    It waits for the browser to close or terminates it when it detects idle status, and then copies the extension into the app’s profile directories. Next, it enables developer mode and adds the extension to Chromium’s Secure Preferences.

    To hide its activity, the malware uses the encryption keys the browser uses to protect sensitive data and then recreates the integrity checks Chrome uses to detect changes in browser preferences.

    This makes the malicious extension appear valid to the browser despite never being approved by the user, a documented but rarely used technique according to the researchers.

    “KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser’s profile directories and registers it in the Secure Preferences file,” Elastic explains.

    “Because Chromium protects these entries with cryptographic integrity checks, the malware must retrieve the required keys and regenerate the associated HMACs and encrypted hashes.”

    Once installed, the extension masquerades as AVSync and performs the following actions:

    • Steals cookies, local storage, and session storage
    • Keylogs text entered into forms, including passwords
    • Captures screenshots and page source
    • Enumerates open tabs and browsing history
    • Intercepts HTTP request bodies and headers
    • Injects attacker-controlled HTML into websites
    • Redirects clicks to attacker-selected destinations
    • Receives commands through a WebSocket connection

    Apart from the malicious extension, the KREMLIN toolkit also acts as an info-stealer that can archive and exfiltrate browser databases, cookies, installed extensions, and the App-Bound cryptographic keys needed to decrypt protected data.

    Overview of the REF9334 attack chain
    Overview of the REF9334 attack chain
    Source: Elastic

    Disrupting the operation

    Elastic Security Labs researchers found that KREMLIN malware campaigns use Ethereum smart contracts as dead-drop resolvers and also abuse the Internet Archive service to host payloads hidden inside JPEG images.

    In more recent campaigns, the threat actor deployed the REMCOS remote access tool, but past operations pushed the Pulsar RAT. According to the researchers, the switch was likely due to REMCOS being more feature rich.

    By connecting the dots through infrastructure analysis and code artifacts, the researchers found the Ethereum wallet that deployed and updated the smart contracts

    According to the researchers, the wallet handled roughly 20,800 USDT (Tether) and 19,000 USDT in incoming and outgoing transfers, respectively. Elastic has confirmed 1,515 infected systems, almost all located in Brazil.

    The security firm disrupted the current KREMLIN campaign by registering a domain that the malware used as an anti-sandbox canary, causing the loader to stop due to false flags on systems that would otherwise qualify for infection.

    Elastic Security Labs researchers shared the tactics and techniques used in KREMLIN attacks, as well as a set of indicators of compromise.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticlePodcast: Humans Are Reading Your ChatGPT Conversations
    Next Article Windows 11 KB5124008 update breaks domain trust for some users
    admin
    • Website

    Related Posts

    News

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    News

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    News

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.