As cited
Copy frozen at (site build).
threat intel
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 uses a toolkit called KREMLIN to deploy malicious Chrome and Edge extensions that extract credentials, session tokens, and sensitive data. The malware bypasses standard browser security checks to force installations without user consent.
Why it matters: Banking customers and any organization using Chrome or Edge face credential theft and session hijacking; practitioners should monitor for KREMLIN deployments, review extension policies, and audit installed extensions for unauthorized additions.
- Source published
- First seen by Cybersecurity Tracker