A trusted browser becomes an invisible gateway for cybercrime.
São Paulo, Brazil.
A sophisticated malware campaign known as KREMLIN is compromising Google Chrome and Microsoft Edge by secretly installing malicious browser extensions capable of stealing passwords, banking credentials and active session information. Cybersecurity researchers at Elastic Security Labs disclosed the operation on September 14, revealing that the attackers have been active since at least May 2025. The investigation identified 1,515 infected systems, approximately 98.75% of them located in Brazil. The findings expose a significant vulnerability in the relationship between browser security mechanisms and the software operating on users’ computers.
The attack begins with deception rather than a conventional browser download. Cybercriminals impersonate financial institutions and distribute files disguised as banking receipts, invoices and commercial documents. When a victim executes the malicious JavaScript file, a multistage infection process downloads additional components and establishes persistence on the computer. Researchers linked the campaign to fraudulent communications impersonating 12 Brazilian banks.
Once installed, KREMLIN monitors the activity of Chromium-based browsers and waits for suitable conditions to modify their configuration. The malware can install its own extension directly into the browser’s profile and manipulate integrity checks so the unauthorized software appears to have been approved by the user. The malicious extension can subsequently operate without a conventional installation request. This technique undermines a security mechanism normally intended to prevent unauthorized modifications.
The information exposed extends far beyond stored passwords. Elastic’s investigation established that the extension can collect authentication cookies, session tokens and information maintained in browser storage. It can also record data entered into online forms, capture screenshots, intercept user interactions and alter the content of visited webpages. These capabilities could allow attackers to impersonate users or manipulate online banking sessions even when the original website is legitimate.
The operation introduces an additional technological complication. KREMLIN uses smart contracts on the Ethereum blockchain to retrieve information about its command-and-control infrastructure, allowing operators to update communication destinations without relying exclusively on fixed servers. Researchers also identified techniques intended to evade automated security analysis. Despite its name, the malware has not been attributed to Russia; the investigation instead identified indicators associated primarily with Brazilian financial targeting.
Elastic Security Labs temporarily disrupted the campaign by registering a domain used by the malware to detect security analysis environments. This intervention caused affected loaders to halt before progressing further, providing defenders with additional time to investigate compromised devices. However, the researchers emphasized that the observed systems remained infected and still required remediation. Disrupting an attack’s communications is not equivalent to removing its malicious components.
For users, the findings reinforce the importance of verifying unexpected financial documents directly with the institution concerned. Suspicious browser extensions should be investigated, operating systems and security software kept updated, and potentially compromised computers subjected to a thorough malware assessment. Removing an unfamiliar extension alone may be insufficient if the underlying infection remains active.
KREMLIN illustrates a broader transformation in cybercrime. Attackers no longer need to compromise a banking website when they can manipulate the browser through which customers access it. Digital security must therefore protect not only information and applications but also the integrity of the computing environment connecting them.
La verdad es estructura, no ruido. / Truth is structure, not noise.