KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
thehackernews.com Sep 15, 2026

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

AI-summarised brief · reviewed before publication

Cybersecurity researchers uncovered the KREMLIN banking malware, active since May 2025, that lures Brazilian bank customers with fake documents and installs a malicious browser extension on Chrome and Edge. The multi‑stage payload uses JavaScript loaders, custom C++ installers, and blockchain‑based command‑and‑control via Ethereum smart contracts to evade detection. The extension bypasses Chromium integrity checks, harvests credentials, session tokens, and browser data, and exfiltrates it to a C2 server while maintaining persistence through scheduled tasks.

💡 Why It Matters

  • · The attack demonstrates how attackers combine browser exploitation with blockchain‑based infrastructure to create a resilient, stealthy threat that can adapt to security updates, posing a significant risk to online banking users worldwide.