← Blog · · df00tech

KREMLIN Toolkit Force-Installs Malicious Chrome and Edge Extensions to Steal Credentials

security-news technique

What happened

According to BleepingComputer, a banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to bypass browser protections and force-install malicious Chrome and Edge extensions on victim machines. The malicious extensions are used to steal credentials, session tokens, and other sensitive data. Details on the specific bypass technique, initial infection vector, and scope of victims were not fully specified in the report.

Why it matters for defenders

Browser extension stores and enterprise policy controls are generally trusted as a gatekeeping layer against unwanted software. A toolkit that can force-install extensions while evading normal browser checks undermines that assumption, giving attackers a persistent foothold inside the browser session itself — the same context where users authenticate to banking portals, SaaS applications, and corporate SSO. Stolen session tokens can enable account takeover even where credentials are protected by MFA, since a valid session can sometimes bypass the need to re-authenticate.

What defenders should watch for or do now

  • Inventory and monitor installed browser extensions across managed endpoints, flagging any extension not present in an approved allowlist.
  • Review Chrome/Edge enterprise policies (e.g., ExtensionInstallForcelist, ExtensionInstallBlocklist) to ensure they haven't been silently modified, and audit the registry/GPO keys that control these policies for unauthorized changes.
  • Hunt for extensions with excessive permissions (e.g., access to all sites, cookies, or webRequest APIs) that were installed outside of normal deployment workflows.
  • Watch for anomalous session token reuse or logins from new devices/IPs shortly after a suspicious extension installation event.
  • Ensure endpoint detection tooling has visibility into browser process behavior and extension directories, since this activity may not trigger traditional file-based malware signatures.

Developing intel

This is a net-new item without an assigned CVE, and public reporting so far is limited to the summary above — technical specifics of the browser-check bypass have not yet been detailed. We will update our coverage as more information becomes available. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.