← Back to Feed

Malware bypasses browser checks to force install Chrome, Edge extensions

September 16, 2026 · BleepingComputer · Severity: HIGH

A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.

Key Takeaways

  • A banking malware operation active since mid-2025 uses the KREMLIN toolkit to bypass browser security checks and forcibly install malicious Chrome and Edge extensions.
  • The malicious extensions steal credentials, session tokens, and sensitive data through a sophisticated malware distribution pipeline targeting online banking users.
  • Users should regularly review browser extension permissions and avoid installing extensions from unverified sources to protect against KREMLIN-style campaigns.
☕ Buy a Coffee