HomeSecurityKREMLIN malware: Malicious extension steals banking sessions

KREMLIN malware: Malicious extension steals banking sessions

KREMLIN malware is a new banking fraud operation targeting Chrome and Edge users in Brazil, installing a malicious extension and stealing credentials, cookies, and active sessions. Elastic Security Labs is tracking the activity as REF9334.

According to technical analysis by The Hacker News, the attackers use deceptive files that resemble bank documents, invoices, or corporate documents. The victim must manually execute a JavaScript file to start the infection chain.

See also: JeetBot: Malicious Twitch extension leaked OAuth tokens of 31,000 users

KREMLIN malware and malicious extension in Chrome and Edge

How does KREMLIN malware work?

The initial JavaScript acts as a multi-stage loader. It checks whether it is running in a virtual machine or in a analytic environment and, if it finds no relevant indications, downloads the next items. It then creates a scheduled task for persistence and looks up the download addresses through smart contracts on Ethereum.

The chain includes a C++ installer, a .NET injector, and the legitimate SentinelMemoryScanner.exe file, which is used for DLL sideloading. The malicious file appears as SentinelAgentCore.dll, and performs new checks for processes, memory, and processors before continuing.

Elastic Security Labs reports that the activity spans seven campaigns over 15 months. Researchers also linked the same infrastructure to distribution of the Pulsar RAT and Remcos RAT, indicating that the operation is not limited to stealing banking sessions.

KREMLIN malware and Ethereum smart contracts for C2 infrastructure

The research places the start of activity at least in May 2025, while the use of Ethereum smart contracts reportedly began on May 19, 2026. This change allows operators to dynamically renew control addresses, without having to redistribute the entire original file.

The malicious add-on generates a unique identifier for each profile and maintains a connection to the control server. Commands can request a snapshot of the active tab, a list of open pages, cookies, local storage, or full HTML code. In this way, an infected device can give access to already logged-in accounts.

Malicious extension bypasses Chrome protection

The key element of the attack is an extension called “AVSync System Inc.” The KREMLIN malware modifies Chromium’s Secure Preferences file, enables developer mode, and recreates the necessary HMAC signatures. This allows the extension to be registered without triggering the usual integrity checks.

After installation, it requests access to tabs, cookies, cached data, and web requests. It can collect credentials, session tokens, history, page content, screenshots, and data from active tabs. Communication with handlers is done via WebSocket, while periodic requests appear as CSS file downloads.

Researchers identified 1,515 infected systems that attempted to connect to an Elastic decoy domain. Over 98% of the systems were located in Brazil, where the attackers used deceptive messages that mimicked a dozen banks. The KREMLIN malware can intercept even the active session, not just the password.

See also: BlueMoon: New exploit kit hits Chrome and Windows with zero-day chain

Protection from KREMLIN malware and browser extensions control

What users and organizations should check

Using Ethereum as an infrastructure discovery mechanism makes it difficult to dismantle control servers. Smart contracts act as a moving list of addresses, allowing attackers to change pickup points without maintaining a fixed infrastructure.

Organizations should restrict extension installation via central policy and check Secure Preferences files for unknown changes. They should also look for suspicious scheduled tasks, sideloading DLLs, and communications from Chrome or Edge profiles that do not match known activity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Users should not open JavaScript files that arrive as invoices or bank documents, even if the message seems urgent. If an unknown extension appears, the device should be immediately isolated, passwords changed from a clean environment and active sessions revoked. The SecNews technical team recommends checking cookies after every suspicious incident.

The technique is reminiscent of previous attacks that exploit stolen cookies, but here the extension maintains access within the browser and can monitor active pages. This increases the risk for online banking accounts, even when the user has enabled multi-factor authentication.

See also: JSCeal Malware: Bypasses Google Authentication with stolen cookies

Elastic's registration of the decoy domain temporarily reduced the effectiveness of anti-sandbox checks and allowed more time for detection and remediation. The finding suggests that monitoring extensions and browser settings changes should be a consistent part of the defense, as hijacking an active session can bypass the value of a strong password.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS