KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Elastic tracks KREMLIN banking malware that used fake Brazilian bank JavaScript lures to deploy malicious Chrome and Edge extensions on 1,515 systems.
Elastic researchers tracked the KREMLIN banking malware operation across seven campaigns over 15 months, infecting 1,515 systems, 98.75% of them in Brazil. Portuguese-language lures posing as bank records and invoices deploy a hostile 'AVSync' extension into Chrome and Edge profiles that harvests passwords, session cookies, keystrokes and screenshots. Loaders check for sandboxes, create scheduled tasks and fetch fresh infrastructure from an Ethereum smart contract; a network canary takeover temporarily disrupted infections.
- The extension requests tabs, cookies, storage and network permissions, captures keystrokes and injects attacker-controlled page content.
- Tampering with Chrome's protected preferences makes the unapproved extension appear legitimate without store installation.
- Blockchain-hosted configuration lets operators rotate infrastructure without rebuilding samples, complicating static blocking.
- Response guidance: isolate devices, remove extensions, reset passwords and revoke sessions from a clean system.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | acrobat-updater.com | n[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l |
| domain | codecaudiog.site | rastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo |
| domain | codecvideowin.online | udiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat- |
| domain | connection.upgradeonline.site | 51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure |
| domain | cremeb.com | itily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure |
| domain | donalurdesconfeitos.site | xtension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur |
| domain | granderevolucao.store | yfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex |
| domain | graph.checkeligibitily.workers.dev | nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[ |
| domain | harialurdes.site | ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16 |
| domain | lojinhadoluiz.online | com Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange |
| domain | luizestrelhashapr.online | gibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura |
| domain | marialurdes.site | tos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[. |
| domain | orange-sun-195a.checkeligibitily.workers.dev | .]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR |
| domain | seguranca.versionnova.site | .]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch |
| domain | volmira.site | derevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct |
| domain | www.creamp1eonlyfans.net | ader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander |
| domain | zaviro.online | n hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra |
| sha256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 | s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8a |
| sha256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c | 70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127 |
| sha256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca | 81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4 |
| sha256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 | fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connec |
| sha256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 | aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c |
| sha256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f | 3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2 |
| sha256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 | 89910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648b |
| sha256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 | a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc |
Full article1,076 words · extracted from cybersecuritynews.com · click to collapse
KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts.
The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and target Chrome and Edge profiles.
The lures are written in Portuguese and impersonate Brazilian banks and payment services. The activity has run across seven campaigns over 15 months. Researchers tracked 1,515 infected systems, 98.75 percent in Brazil.
Elastic said in a report shared with Cyber Security News (CSN) that their takeover of a network canary temporarily stopped those infections from advancing.
The name KREMLIN does not point to a Russian operation. Researchers assess the campaign is focused on Brazil, based on its language, bank-themed decoys, and activity patterns.
Its danger lies in combining familiar social engineering with browser-level access, a route that can bypass the caution users normally apply to suspicious log-in pages.
KREMLIN Banking Malware Infects Over 1,500 Systems
After an initial victim executes the lure, KREMLIN uses several stages to avoid analysis and load its installer. It checks whether the system looks like a sandbox, creates a scheduled task, and retrieves fresh hosting details from an Ethereum smart contract.
That setup makes it easier for operators to change infrastructure without rebuilding every sample. The installer copies the extension into Chrome and Edge profile folders, bypassing the official store.
It alters Chrome’s protected preferences and recreates the checks that normally verify extension settings. That allows the browser to treat the add-on as approved, even though the user never installed it.
.webp)
The extension poses as AVSync and requests access to tabs, cookies, browser storage, and network requests. It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.
Similar Brazilian browser extension attacks show why browser add-ons have become a valuable path to banking credentials.
It also archives browser databases and encryption keys before sending the data remotely. A stolen session cookie can let an intruder reuse an authenticated account.
Readers can compare the broader risk in malicious Chrome extension campaigns, where extensions abused extensive browser permissions to collect sensitive information.
Banking Lures and Response
Operators have evolved the toolkit since May 2025. Earlier campaigns delivered other remote access tools alongside malicious extensions, while newer activity used blockchain-hosted configuration and a signed security-program component to load an unsigned malicious file.
The shared infrastructure suggests coordinated control of the infection chain. The latest campaign targeted Brazilian users with filenames resembling receipts, payment records, bank statements, and instant-payment documents.
.webp)
A fake error message can conceal the infection. That blend of believable paperwork and silent installation makes ordinary file-opening habits a security concern. Organizations should alert staff that banks and payment providers do not normally send JavaScript files as documents.
They should block script files received through email or messaging where possible, inspect scheduled tasks and browser profiles for unauthorized changes, and hunt for the indicators below.
Teams responding to a suspected infection should isolate the device, remove the malicious extension, reset affected passwords from a clean system, and revoke active sessions.
Users should review every installed browser extension and remove unfamiliar entries, especially add-ons with broad access to websites, cookies, or tabs. Use official banking apps or bookmarked sites, not message links.
This advice aligns with lessons from extensions stealing passwords and sessions, where changing credentials and revoking sessions from a clean device were critical after exposure. The temporary canary disruption gives defenders time, not a guarantee that the threat is gone.
KREMLIN’s use of changeable online configuration means defenders need to watch for behavior as well as block known infrastructure. Browser reviews, email filtering, endpoint monitoring, and session revocation can limit damage.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 | KREMLIN JavaScript loader sample |
| SHA-256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 | First-stage popup JavaScript sample |
| SHA-256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 | KREMLIN x64 extension installer binary |
| SHA-256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca | Malicious AVSync extension sample |
| SHA-256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f | Related Wave A loader sample |
| SHA-256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 | Related Wave B loader sample |
| SHA-256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c | Related Wave C loader sample |
| SHA-256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 | PowerShell extension-installer implementation |
| Domain | connection[.]upgradeonline[.]site | Loader beaconing and extension-delivery infrastructure |
| Domain | www[.]creamp1eonlyfans[.]net | Network canary domain checked by KREMLIN |
| Domain | granderevolucao[.]store | Installer payload-hosting domain |
| Domain | volmira[.]site | Extension hosting and credential-exfiltration infrastructure |
| Domain | zaviro[.]online | Exfiltration and fingerprinting infrastructure |
| Domain | graph[.]checkeligibitily[.]workers[.]dev | Extension endpoint resolver |
| Domain | luizestrelhashapr[.]online | Resolved WebSocket command-and-control host |
| Domain | seguranca[.]versionnova[.]site | Infrastructure associated with a related KREMLIN branch |
| Domain | codecaudiog[.]site | Earlier KREMLIN campaign staging domain |
| Domain | codecvideowin[.]online | Earlier campaign extension-hosting domain |
| Domain | acrobat-updater[.]com | Earlier campaign lure and payload-hosting domain |
| Domain | lojinhadoluiz[.]online | FrameSync campaign extension infrastructure |
| Domain | orange-sun-195a[.]checkeligibitily[.]workers[.]dev | FrameSync campaign C2 resolver |
| Domain | cremeb[.]com | QR-extension and earlier KREMLIN campaign infrastructure |
| Domain | donalurdesconfeitos[.]site | Earlier extension-delivery infrastructure |
| Domain | marialurdes[.]site | Intermediate KREMLIN campaign domain |
| Domain | harialurdes[.]site | Intermediate KREMLIN campaign domain |
| IP address | 178.92.162[.]38:443 | REMCOS RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:4782 | Earlier PULSAR RAT command-and-control endpoint |
| IP address | 185.221.23[.]133:443 | Earlier PULSAR RAT command-and-control endpoint |
| IP address | 144.172.112[.]239:4782 | Acrobat campaign PULSAR RAT endpoint |
| IP address | 45.90.13[.]210:443 | Acrobat campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]100:443 | Cremeb campaign PULSAR RAT endpoint |
| IP address | 37.16.74[.]34:443 | Cremeb campaign PULSAR RAT endpoint |
| Ethereum smart contract | 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b | Active KREMLIN configuration dead-drop resolver |
| Chrome extension ID | ndpbidppejfanjbhfgjlohfanbfbklff | AVSync malicious extension ID |
| Chrome extension ID | djodclnjknbpambeaaapadmdfhmbpeog | FrameSync malicious extension ID |
| Chrome extension ID | cdgcjghdeinagopbaobhmaefigoafaaa | QR-themed malicious extension ID |
| File name | SentinelMemoryScanner.exe | Signed binary abused for DLL side-loading |
| File name | SentinelAgentCore.dll | Unsigned KREMLIN payload masquerading as a legitimate DLL |
| File name | MicrosoftNodeRuntimeUpdater | Scheduled-task name used for persistence |
| File name | output_image_202505.jpg | Earlier Internet Archive-hosted RunPE module |
| File name | hotelmoskva.jpg | JPEG carrier used to conceal a .NET injector |
| File name | tragira.jpg | JPEG carrier used in the Acrobat campaign |
| Mutex | ClarinhoQueSim-XEDA2O | KREMLIN campaign mutex |
| Customer ID | 98d8049e-804f-11f1-b79f-ae3a8bb85d01 | Identifier associated with the current campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/kremlin-banking-malware/