KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts.
The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and target Chrome and Edge profiles.
The lures are written in Portuguese and impersonate Brazilian banks and payment services. The activity has run across seven campaigns over 15 months. Researchers tracked 1,515 infected systems, 98.75 percent in Brazil.
Elastic said in a report shared with Cyber Security News (CSN) that their takeover of a network canary temporarily stopped those infections from advancing.
The name KREMLIN does not point to a Russian operation. Researchers assess the campaign is focused on Brazil, based on its language, bank-themed decoys, and activity patterns.
Its danger lies in combining familiar social engineering with browser-level access, a route that can bypass the caution users normally apply to suspicious log-in pages.
KREMLIN Banking Malware Infects Over 1,500 Systems
After an initial victim executes the lure, KREMLIN uses several stages to avoid analysis and load its installer. It checks whether the system looks like a sandbox, creates a scheduled task, and retrieves fresh hosting details from an Ethereum smart contract.
That setup makes it easier for operators to change infrastructure without rebuilding every sample. The installer copies the extension into Chrome and Edge profile folders, bypassing the official store.
It alters Chrome’s protected preferences and recreates the checks that normally verify extension settings. That allows the browser to treat the add-on as approved, even though the user never installed it.

The extension poses as AVSync and requests access to tabs, cookies, browser storage, and network requests. It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.
Similar Brazilian browser extension attacks show why browser add-ons have become a valuable path to banking credentials.
It also archives browser databases and encryption keys before sending the data remotely. A stolen session cookie can let an intruder reuse an authenticated account.
Readers can compare the broader risk in malicious Chrome extension campaigns, where extensions abused extensive browser permissions to collect sensitive information.
Banking Lures and Response
Operators have evolved the toolkit since May 2025. Earlier campaigns delivered other remote access tools alongside malicious extensions, while newer activity used blockchain-hosted configuration and a signed security-program component to load an unsigned malicious file.
The shared infrastructure suggests coordinated control of the infection chain. The latest campaign targeted Brazilian users with filenames resembling receipts, payment records, bank statements, and instant-payment documents.

A fake error message can conceal the infection. That blend of believable paperwork and silent installation makes ordinary file-opening habits a security concern. Organizations should alert staff that banks and payment providers do not normally send JavaScript files as documents.
They should block script files received through email or messaging where possible, inspect scheduled tasks and browser profiles for unauthorized changes, and hunt for the indicators below.
Teams responding to a suspected infection should isolate the device, remove the malicious extension, reset affected passwords from a clean system, and revoke active sessions.
Users should review every installed browser extension and remove unfamiliar entries, especially add-ons with broad access to websites, cookies, or tabs. Use official banking apps or bookmarked sites, not message links.
This advice aligns with lessons from extensions stealing passwords and sessions, where changing credentials and revoking sessions from a clean device were critical after exposure. The temporary canary disruption gives defenders time, not a guarantee that the threat is gone.
KREMLIN’s use of changeable online configuration means defenders need to watch for behavior as well as block known infrastructure. Browser reviews, email filtering, endpoint monitoring, and session revocation can limit damage.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 |
KREMLIN JavaScript loader sample |
| SHA-256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 |
First-stage popup JavaScript sample |
| SHA-256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 |
KREMLIN x64 extension installer binary |
| SHA-256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca |
Malicious AVSync extension sample |
| SHA-256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f |
Related Wave A loader sample |
| SHA-256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 |
Related Wave B loader sample |
| SHA-256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c |
Related Wave C loader sample |
| SHA-256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 |
PowerShell extension-installer implementation |
| Domain | connection[.]upgradeonline[.]site |
Loader beaconing and extension-delivery infrastructure |
| Domain | www[.]creamp1eonlyfans[.]net |
Network canary domain checked by KREMLIN |
| Domain | granderevolucao[.]store |
Installer payload-hosting domain |
| Domain | volmira[.]site |
Extension hosting and credential-exfiltration infrastructure |
| Domain | zaviro[.]online |
Exfiltration and fingerprinting infrastructure |
| Domain | graph[.]checkeligibitily[.]workers[.]dev |
Extension endpoint resolver |
| Domain | luizestrelhashapr[.]online |
Resolved WebSocket command-and-control host |
| Domain | seguranca[.]versionnova[.]site |
Infrastructure associated with a related KREMLIN branch |
| Domain | codecaudiog[.]site |
Earlier KREMLIN campaign staging domain |
| Domain | codecvideowin[.]online |
Earlier campaign extension-hosting domain |
| Domain | acrobat-updater[.]com |
Earlier campaign lure and payload-hosting domain |
| Domain | lojinhadoluiz[.]online |
FrameSync campaign extension infrastructure |
| Domain | orange-sun-195a[.]checkeligibitily[.]workers[.]dev |
FrameSync campaign C2 resolver |
| Domain | cremeb[.]com |
QR-extension and earlier KREMLIN campaign infrastructure |
| Domain | donalurdesconfeitos[.]site |
Earlier extension-delivery infrastructure |
| Domain | marialurdes[.]site |
Intermediate KREMLIN campaign domain |
| Domain | harialurdes[.]site |
Intermediate KREMLIN campaign domain |
| IP address | 178.92.162[.]38:443 |
REMCOS RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:4782 |
Earlier PULSAR RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:443 |
Earlier PULSAR RAT command-and-control endpoint |
| IP address | 144.172.112[.]239:4782 |
Acrobat campaign PULSAR RAT endpoint |
| IP address | 45.90.13[.]210:443 |
Acrobat campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]100:443 |
Cremeb campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]34:443 |
Cremeb campaign PULSAR RAT endpoint |
| Ethereum smart contract | 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b |
Active KREMLIN configuration dead-drop resolver |
| Chrome extension ID | ndpbidppejfanjbhfgjlohfanbfbklff |
AVSync malicious extension ID |
| Chrome extension ID | djodclnjknbpambeaaapadmdfhmbpeog |
FrameSync malicious extension ID |
| Chrome extension ID | cdgcjghdeinagopbaobhmaefigoafaaa |
QR-themed malicious extension ID |
| File name | SentinelMemoryScanner.exe |
Signed binary abused for DLL side-loading |
| File name | SentinelAgentCore.dll |
Unsigned KREMLIN payload masquerading as a legitimate DLL |
| File name | MicrosoftNodeRuntimeUpdater |
Scheduled-task name used for persistence |
| File name | output_image_202505.jpg |
Earlier Internet Archive-hosted RunPE module |
| File name | hotelmoskva.jpg |
JPEG carrier used to conceal a .NET injector |
| File name | tragira.jpg |
JPEG carrier used in the Acrobat campaign |
| Mutex | ClarinhoQueSim-XEDA2O |
KREMLIN campaign mutex |
| Customer ID | 98d8049e-804f-11f1-b79f-ae3a8bb85d01 |
Identifier associated with the current campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension appeared first on Cyber Security News.
