CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Malware bypasses browser checks to force install Chrome, Edge extensions

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7544

As cited

Copy frozen at (site build).

threat intel

Malware bypasses browser checks to force install Chrome, Edge extensions

A banking malware operation active since mid-2025 uses a toolkit called KREMLIN to deploy malicious Chrome and Edge extensions that extract credentials, session tokens, and sensitive data. The malware bypasses standard browser security checks to force installations without user consent.

Why it matters: Banking customers and any organization using Chrome or Edge face credential theft and session hijacking; practitioners should monitor for KREMLIN deployments, review extension policies, and audit installed extensions for unauthorized additions.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary