KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts.

The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and target Chrome and Edge profiles.

The lures are written in Portuguese and impersonate Brazilian banks and payment services. The activity has run across seven campaigns over 15 months. Researchers tracked 1,515 infected systems, 98.75 percent in Brazil.

Elastic said in a report shared with Cyber Security News (CSN) that their takeover of a network canary temporarily stopped those infections from advancing.

The name KREMLIN does not point to a Russian operation. Researchers assess the campaign is focused on Brazil, based on its language, bank-themed decoys, and activity patterns.

Its danger lies in combining familiar social engineering with browser-level access, a route that can bypass the caution users normally apply to suspicious log-in pages.

KREMLIN Banking Malware Infects Over 1,500 Systems

After an initial victim executes the lure, KREMLIN uses several stages to avoid analysis and load its installer. It checks whether the system looks like a sandbox, creates a scheduled task, and retrieves fresh hosting details from an Ethereum smart contract.

That setup makes it easier for operators to change infrastructure without rebuilding every sample. The installer copies the extension into Chrome and Edge profile folders, bypassing the official store.

It alters Chrome’s protected preferences and recreates the checks that normally verify extension settings. That allows the browser to treat the add-on as approved, even though the user never installed it.

Infection chain (Source - Elastic)
Infection chain (Source – Elastic)

The extension poses as AVSync and requests access to tabs, cookies, browser storage, and network requests. It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.

Similar Brazilian browser extension attacks show why browser add-ons have become a valuable path to banking credentials.

It also archives browser databases and encryption keys before sending the data remotely. A stolen session cookie can let an intruder reuse an authenticated account.

Readers can compare the broader risk in malicious Chrome extension campaigns, where extensions abused extensive browser permissions to collect sensitive information.

Banking Lures and Response

Operators have evolved the toolkit since May 2025. Earlier campaigns delivered other remote access tools alongside malicious extensions, while newer activity used blockchain-hosted configuration and a signed security-program component to load an unsigned malicious file.

The shared infrastructure suggests coordinated control of the infection chain. The latest campaign targeted Brazilian users with filenames resembling receipts, payment records, bank statements, and instant-payment documents.

Playground platform for testing the malicious extension features (Source - Elastic)
Playground platform for testing the malicious extension features (Source – Elastic)

A fake error message can conceal the infection. That blend of believable paperwork and silent installation makes ordinary file-opening habits a security concern. Organizations should alert staff that banks and payment providers do not normally send JavaScript files as documents.

They should block script files received through email or messaging where possible, inspect scheduled tasks and browser profiles for unauthorized changes, and hunt for the indicators below.

Teams responding to a suspected infection should isolate the device, remove the malicious extension, reset affected passwords from a clean system, and revoke active sessions.

Users should review every installed browser extension and remove unfamiliar entries, especially add-ons with broad access to websites, cookies, or tabs. Use official banking apps or bookmarked sites, not message links.

This advice aligns with lessons from extensions stealing passwords and sessions, where changing credentials and revoking sessions from a clean device were critical after exposure. The temporary canary disruption gives defenders time, not a guarantee that the threat is gone.

KREMLIN’s use of changeable online configuration means defenders need to watch for behavior as well as block known infrastructure. Browser reviews, email filtering, endpoint monitoring, and session revocation can limit damage.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample
SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample
SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary
SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample
SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample
SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample
SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample
SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation
Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure
Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN
Domain granderevolucao[.]store Installer payload-hosting domain
Domain volmira[.]site Extension hosting and credential-exfiltration infrastructure
Domain zaviro[.]online Exfiltration and fingerprinting infrastructure
Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver
Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host
Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch
Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain
Domain codecvideowin[.]online Earlier campaign extension-hosting domain
Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain
Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure
Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver
Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure
Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure
Domain marialurdes[.]site Intermediate KREMLIN campaign domain
Domain harialurdes[.]site Intermediate KREMLIN campaign domain
IP address 178.92.162[.]38:443 REMCOS RAT command-and-control endpoint
IP address 185.221.23[.]133:4782 Earlier PULSAR RAT command-and-control endpoint
IP address 185.221.23[.]133:443 Earlier PULSAR RAT command-and-control endpoint
IP address 144.172.112[.]239:4782 Acrobat campaign PULSAR RAT endpoint
IP address 45.90.13[.]210:443 Acrobat campaign PULSAR RAT endpoint
IP address 37.16.74[.]100:443 Cremeb campaign PULSAR RAT endpoint
IP address 37.16.74[.]34:443 Cremeb campaign PULSAR RAT endpoint
Ethereum smart contract 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b Active KREMLIN configuration dead-drop resolver
Chrome extension ID ndpbidppejfanjbhfgjlohfanbfbklff AVSync malicious extension ID
Chrome extension ID djodclnjknbpambeaaapadmdfhmbpeog FrameSync malicious extension ID
Chrome extension ID cdgcjghdeinagopbaobhmaefigoafaaa QR-themed malicious extension ID
File name SentinelMemoryScanner.exe Signed binary abused for DLL side-loading
File name SentinelAgentCore.dll Unsigned KREMLIN payload masquerading as a legitimate DLL
File name MicrosoftNodeRuntimeUpdater Scheduled-task name used for persistence
File name output_image_202505.jpg Earlier Internet Archive-hosted RunPE module
File name hotelmoskva.jpg JPEG carrier used to conceal a .NET injector
File name tragira.jpg JPEG carrier used in the Acrobat campaign
Mutex ClarinhoQueSim-XEDA2O KREMLIN campaign mutex
Customer ID 98d8049e-804f-11f1-b79f-ae3a8bb85d01 Identifier associated with the current campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension appeared first on Cyber Security News.