KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
AI-summarised brief · reviewed before publication
Cybersecurity researchers uncovered the KREMLIN banking malware, active since May 2025, that lures Brazilian bank customers with fake documents and installs a malicious browser extension on Chrome and Edge. The multi‑stage payload uses JavaScript loaders, custom C++ installers, and blockchain‑based command‑and‑control via Ethereum smart contracts to evade detection. The extension bypasses Chromium integrity checks, harvests credentials, session tokens, and browser data, and exfiltrates it to a C2 server while maintaining persistence through scheduled tasks.
💡 Why It Matters
- · The attack demonstrates how attackers combine browser exploitation with blockchain‑based infrastructure to create a resilient, stealthy threat that can adapt to security updates, posing a significant risk to online banking users worldwide.