
Hackers are quietly force-installing malicious Chrome and Edge extensions that steal passwords, cookies and session data without victims approving them, according to a new report.
Elastic Security Labs says the KREMLIN bank malware toolkit has powered at least seven campaigns since May of 2025 that impersonate 12 Brazilian banks.
The infection starts when a user opens a JavaScript file disguised as a bank receipt, invoice or business document.
After sandbox checks, the malware copies an extension into the browser’s profile folders, edits the Secure Preferences file and regenerates integrity hashes so Chrome and Edge load it as if the user approved it.
Says Elastic Security Labs,
“KREMLIN uses a documented technique rarely observed in malware: it manually copies the extension into the browser’s profile directories and registers it in the Secure Preferences file…
Once installed, the extension masks as AVSync and performs various actions. It steals cookies, local storage, and session storage. It keylogs text entered into forms, including passwords.”
The extension can also capture screenshots, intercept HTTP traffic, inject attacker HTML, redirect clicks and take WebSocket commands.
Researchers disrupted the current campaign by registering an anti-sandbox canary domain, temporarily blocking more than 1,500 infections. Nearly all of those check-ins came from Brazil.
The banks include Banco do Brasil, Caixa, Bradesco, Sicoob, C6 Bank, Inter, BTG, Safra, PagBank, PicPay, Santander and Mercado Pago.
Elastic Security Labs is the research arm of the search and security company Elastic.
Follow us on X, Facebook and Telegram
Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
The post Hackers Force-Installing Chrome Extensions That Steal Bank Passwords and Login Sessions: Report appeared first on The Daily Hodl.



Comments (0)
Please sign in to comment.
No comments yet. Be the first to comment.