KREMLIN toolkit forces fake Chrome and Edge extensions onto Brazilian banking targets
Elastic Security Labs uncovered a malware toolkit called KREMLIN, active since mid-2025, that tricks victims into opening fake invoice or receipt files to install malicious Chrome and Edge extensions without any user approval. The toolkit recreates Chromium's cryptographic integrity checks so the browser treats the rogue extension as legitimate, then harvests login credentials, session tokens and other sensitive data. Elastic ties the operation to a Brazilian group that has run at least seven campaigns impersonating 12 banks since May.