Chrome and Edge Targeted by KREMLIN Malware to Steal Passwords and Session Tokens
Your browser is probably one of the most important gateways to your digital life. Chrome or Edge may be used for email, social media, cloud storage, online shopping, work accounts, and even online banking.
That convenience also makes browsers valuable targets for malware.
Security researchers have uncovered a campaign involving a malware toolkit known as KREMLIN, which uses malicious browser extensions to target sensitive information stored or handled by Chrome and Edge.
KREMLIN Malware Targets Chrome and Edge
According to reporting from TechRadar and research from Elastic Security Labs, the operation tracked as REF9334 has been active since at least May 2025.
The campaign uses a malicious browser extension capable of operating inside Google Chrome and Microsoft Edge.
One important clarification: the name KREMLIN does not mean the malware is connected to Russia. Elastic says the name comes from the toolkit's own identifier, while the campaign itself is associated with a Brazilian operation targeting banking users.
It Is Not Just Passwords
The campaign is particularly concerning because it goes after more than traditional login credentials.
- Browser credentials
- Cookies
- Session information and tokens
- Browsing activity
- Information from visited websites
- Screenshots
Session tokens can be especially valuable because they may allow attackers to abuse an already authenticated session without simply relying on the victim's password.
That is why changing a password after a suspected compromise is only part of the response. Active sessions and suspicious devices should also be reviewed.
The Infection Can Start With an Ordinary-Looking File
The infection chain relies heavily on social engineering.
Victims may receive JavaScript files disguised as invoices, bank documents, payment records, or business files.
Once executed, the malware can retrieve additional components and establish persistence on the compromised machine.
Researchers also observed anti-sandbox behavior. The malware checks whether it appears to be running inside an analysis environment and can stop when it detects conditions associated with security research.
A Fake Extension Called AVSync System Inc.
One of the more deceptive parts of the campaign is the malicious extension name: AVSync System Inc.
The name can make the extension look like a legitimate security or antivirus component.
For ordinary users, that can be enough to lower suspicion.
This is why checking an extension's name alone is not enough. Users should also examine its developer, source, permissions, and whether they actually installed it themselves.
How Does the Malware Reach Chrome and Edge?
Elastic researchers found that the toolkit can bypass Chromium integrity mechanisms and make the browser load the malicious extension as if it had been approved by the user.
That makes the attack different from the familiar scenario where someone knowingly clicks an Install extension button.
Browser security therefore cannot depend solely on manually removing suspicious extensions. The operating system, downloaded files, and installed software all matter.
Most Identified Victims Were in Brazil
During the investigation, Elastic identified approximately 1,515 infected systems through infrastructure it was able to take control of for research purposes. Around 98 percent of those systems were located in Brazil.
That does not mean Chrome and Edge users elsewhere face the same level of exposure. Instead, it shows that this particular campaign has a strong geographic focus.
However, the techniques remain relevant internationally because the same malware delivery methods could potentially be adapted for other targets.
Ethereum Is Used to Help Hide the Command Infrastructure
Another unusual element of the campaign is how it retrieves command-and-control information.
Instead of relying entirely on a fixed server address, the operators use Ethereum smart contracts to store configuration information.
This approach can make the infrastructure harder to disrupt because blocking a single server may not be enough to stop infected machines from discovering their next destination.
In this case, blockchain technology is being used as part of the malware's infrastructure rather than simply as a financial tool.
Why Are Session Tokens So Valuable?
Think about what happens after you successfully log in to an online service.
Your browser receives information that allows the service to recognize your authenticated session. You do not need to enter your password again every time you open another page.
If attackers obtain the relevant session information, they may attempt to abuse that authenticated state.
This is one reason modern account security cannot focus exclusively on passwords.
Using unique passwords and managing credentials carefully is still important. A password manager can help organize unique credentials without forcing you to memorize dozens of passwords.
What Should Chrome and Edge Users Do?
There is no reason to panic simply because you use Chrome or Edge. This report concerns a specific malware campaign and does not mean that the browsers themselves are automatically compromised.
Instead, focus on reducing the opportunities malware has to enter your system.
- Avoid suspicious files. Be careful with invoices, payment documents, and business files received from unknown sources.
- Review browser extensions. Remove extensions you do not recognize or no longer need.
- Check extension permissions. Extensions with broad access to websites and browsing data deserve closer scrutiny.
- Keep software updated. Install available browser and operating system security updates.
- Review active sessions. If you suspect an infected device, sign out of important accounts and investigate unusual sessions.
- Use additional authentication. MFA can provide another layer of protection when credentials are compromised.
Do Not Ignore Strange Browser Behavior
Unexpected redirects, unfamiliar extensions, unusual login activity, or repeated account sign-outs can all be reasons to investigate.
None of these symptoms automatically proves that KREMLIN malware is present. But unusual behavior should not simply be ignored.
The same lesson applies to messages claiming that your authentication settings or passkey need an urgent update. Attackers increasingly use legitimate security concepts as social-engineering bait. You can also read our coverage of passkey-themed phishing attacks to see how this tactic works.
The Bigger Problem Is Not Chrome or Edge
The KREMLIN campaign highlights an important reality about modern browsers: they are extremely convenient because they store and handle a huge amount of useful information.
Passwords, cookies, active sessions, browsing data, and account integrations make everyday internet use easier.
Those same capabilities can become valuable targets when a device is compromised.
That means browser security should be treated as part of your overall account security strategy.
Do not only ask whether your password is secure. Also ask whether your device, browser, extensions, cookies, and active sessions are secure.
KREMLIN may currently be strongly associated with banking targets in Brazil, but the campaign offers a useful reminder for anyone who relies heavily on a browser for sensitive digital activity.

Post a Comment for "Chrome and Edge Targeted by KREMLIN Malware to Steal Passwords and Session Tokens"