← Back to Feed
Malware bypasses browser checks to force install Chrome, Edge extensions
September 16, 2026 · BleepingComputer · Severity: HIGH
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.
Key Takeaways
- A banking malware operation active since mid-2025 uses the KREMLIN toolkit to bypass browser security checks and forcibly install malicious Chrome and Edge extensions.
- The malicious extensions steal credentials, session tokens, and sensitive data through a sophisticated malware distribution pipeline targeting online banking users.
- Users should regularly review browser extension permissions and avoid installing extensions from unverified sources to protect against KREMLIN-style campaigns.