ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta

KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension

mediumMalware exploited in the wildimportance 52
AI summary · glm-5.3-flash

Elastic tracks KREMLIN banking malware that used fake Brazilian bank JavaScript lures to deploy malicious Chrome and Edge extensions on 1,515 systems.

Elastic researchers tracked the KREMLIN banking malware operation across seven campaigns over 15 months, infecting 1,515 systems, 98.75% of them in Brazil. Portuguese-language lures posing as bank records and invoices deploy a hostile 'AVSync' extension into Chrome and Edge profiles that harvests passwords, session cookies, keystrokes and screenshots. Loaders check for sandboxes, create scheduled tasks and fetch fresh infrastructure from an Ethereum smart contract; a network canary takeover temporarily disrupted infections.

  • The extension requests tabs, cookies, storage and network permissions, captures keystrokes and injects attacker-controlled page content.
  • Tampering with Chrome's protected preferences makes the unapproved extension appear legitimate without store installation.
  • Blockchain-hosted configuration lets operators rotate infrastructure without rebuilding samples, complicating static blocking.
  • Response guidance: isolate devices, remove extensions, reset passwords and revoke sessions from a clean system.
VendorsElastic
MalwareKREMLIN
OrganizationsElastic
CountriesBrazil

Indicators of compromiseAll →

TypeIndicatorContext
domainacrobat-updater.comn[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l
domaincodecaudiog.siterastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo
domaincodecvideowin.onlineudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat-
domainconnection.upgradeonline.site51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure
domaincremeb.comitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure
domaindonalurdesconfeitos.sitextension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur
domaingranderevolucao.storeyfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex
domaingraph.checkeligibitily.workers.devnline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[
domainharialurdes.siteialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16
domainlojinhadoluiz.onlinecom Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange
domainluizestrelhashapr.onlinegibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura
domainmarialurdes.sitetos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.
domainorange-sun-195a.checkeligibitily.workers.dev.]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR
domainseguranca.versionnova.site.]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch
domainvolmira.sitederevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct
domainwww.creamp1eonlyfans.netader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander
domainzaviro.onlinen hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra
sha256106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8a
sha256170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127
sha256223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4
sha25642a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connec
sha2565ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c
sha256ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2
sha256c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a426889910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648b
sha256cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc
Full article1,076 words · extracted from cybersecuritynews.com · click to collapse

KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts.

The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and target Chrome and Edge profiles.

The lures are written in Portuguese and impersonate Brazilian banks and payment services. The activity has run across seven campaigns over 15 months. Researchers tracked 1,515 infected systems, 98.75 percent in Brazil.

Elastic said in a report shared with Cyber Security News (CSN) that their takeover of a network canary temporarily stopped those infections from advancing.

The name KREMLIN does not point to a Russian operation. Researchers assess the campaign is focused on Brazil, based on its language, bank-themed decoys, and activity patterns.

Its danger lies in combining familiar social engineering with browser-level access, a route that can bypass the caution users normally apply to suspicious log-in pages.

KREMLIN Banking Malware Infects Over 1,500 Systems

After an initial victim executes the lure, KREMLIN uses several stages to avoid analysis and load its installer. It checks whether the system looks like a sandbox, creates a scheduled task, and retrieves fresh hosting details from an Ethereum smart contract.

That setup makes it easier for operators to change infrastructure without rebuilding every sample. The installer copies the extension into Chrome and Edge profile folders, bypassing the official store.

It alters Chrome’s protected preferences and recreates the checks that normally verify extension settings. That allows the browser to treat the add-on as approved, even though the user never installed it.

Infection chain (Source - Elastic)
Infection chain (Source – Elastic)

The extension poses as AVSync and requests access to tabs, cookies, browser storage, and network requests. It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.

Similar Brazilian browser extension attacks show why browser add-ons have become a valuable path to banking credentials.

It also archives browser databases and encryption keys before sending the data remotely. A stolen session cookie can let an intruder reuse an authenticated account.

Readers can compare the broader risk in malicious Chrome extension campaigns, where extensions abused extensive browser permissions to collect sensitive information.

Banking Lures and Response

Operators have evolved the toolkit since May 2025. Earlier campaigns delivered other remote access tools alongside malicious extensions, while newer activity used blockchain-hosted configuration and a signed security-program component to load an unsigned malicious file.

The shared infrastructure suggests coordinated control of the infection chain. The latest campaign targeted Brazilian users with filenames resembling receipts, payment records, bank statements, and instant-payment documents.

Playground platform for testing the malicious extension features (Source - Elastic)
Playground platform for testing the malicious extension features (Source – Elastic)

A fake error message can conceal the infection. That blend of believable paperwork and silent installation makes ordinary file-opening habits a security concern. Organizations should alert staff that banks and payment providers do not normally send JavaScript files as documents.

They should block script files received through email or messaging where possible, inspect scheduled tasks and browser profiles for unauthorized changes, and hunt for the indicators below.

Teams responding to a suspected infection should isolate the device, remove the malicious extension, reset affected passwords from a clean system, and revoke active sessions.

Users should review every installed browser extension and remove unfamiliar entries, especially add-ons with broad access to websites, cookies, or tabs. Use official banking apps or bookmarked sites, not message links.

This advice aligns with lessons from extensions stealing passwords and sessions, where changing credentials and revoking sessions from a clean device were critical after exposure. The temporary canary disruption gives defenders time, not a guarantee that the threat is gone.

KREMLIN’s use of changeable online configuration means defenders need to watch for behavior as well as block known infrastructure. Browser reviews, email filtering, endpoint monitoring, and session revocation can limit damage.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-256106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42KREMLIN JavaScript loader sample
SHA-2565ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552First-stage popup JavaScript sample
SHA-256c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268KREMLIN x64 extension installer binary
SHA-256223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7caMalicious AVSync extension sample
SHA-256ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5fRelated Wave A loader sample
SHA-256cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0Related Wave B loader sample
SHA-256170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2cRelated Wave C loader sample
SHA-25642a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9PowerShell extension-installer implementation
Domainconnection[.]upgradeonline[.]siteLoader beaconing and extension-delivery infrastructure
Domainwww[.]creamp1eonlyfans[.]netNetwork canary domain checked by KREMLIN
Domaingranderevolucao[.]storeInstaller payload-hosting domain
Domainvolmira[.]siteExtension hosting and credential-exfiltration infrastructure
Domainzaviro[.]onlineExfiltration and fingerprinting infrastructure
Domaingraph[.]checkeligibitily[.]workers[.]devExtension endpoint resolver
Domainluizestrelhashapr[.]onlineResolved WebSocket command-and-control host
Domainseguranca[.]versionnova[.]siteInfrastructure associated with a related KREMLIN branch
Domaincodecaudiog[.]siteEarlier KREMLIN campaign staging domain
Domaincodecvideowin[.]onlineEarlier campaign extension-hosting domain
Domainacrobat-updater[.]comEarlier campaign lure and payload-hosting domain
Domainlojinhadoluiz[.]onlineFrameSync campaign extension infrastructure
Domainorange-sun-195a[.]checkeligibitily[.]workers[.]devFrameSync campaign C2 resolver
Domaincremeb[.]comQR-extension and earlier KREMLIN campaign infrastructure
Domaindonalurdesconfeitos[.]siteEarlier extension-delivery infrastructure
Domainmarialurdes[.]siteIntermediate KREMLIN campaign domain
Domainharialurdes[.]siteIntermediate KREMLIN campaign domain
IP address178.92.162[.]38:443REMCOS RAT command-and-control endpoint
IP address185.221.23[.]133:4782Earlier PULSAR RAT command-and-control endpoint
IP address185.221.23[.]133:443Earlier PULSAR RAT command-and-control endpoint
IP address144.172.112[.]239:4782Acrobat campaign PULSAR RAT endpoint
IP address45.90.13[.]210:443Acrobat campaign PULSAR RAT endpoint
IP address37.16.74[.]100:443Cremeb campaign PULSAR RAT endpoint
IP address37.16.74[.]34:443Cremeb campaign PULSAR RAT endpoint
Ethereum smart contract0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07bActive KREMLIN configuration dead-drop resolver
Chrome extension IDndpbidppejfanjbhfgjlohfanbfbklffAVSync malicious extension ID
Chrome extension IDdjodclnjknbpambeaaapadmdfhmbpeogFrameSync malicious extension ID
Chrome extension IDcdgcjghdeinagopbaobhmaefigoafaaaQR-themed malicious extension ID
File nameSentinelMemoryScanner.exeSigned binary abused for DLL side-loading
File nameSentinelAgentCore.dllUnsigned KREMLIN payload masquerading as a legitimate DLL
File nameMicrosoftNodeRuntimeUpdaterScheduled-task name used for persistence
File nameoutput_image_202505.jpgEarlier Internet Archive-hosted RunPE module
File namehotelmoskva.jpgJPEG carrier used to conceal a .NET injector
File nametragira.jpgJPEG carrier used in the Acrobat campaign
MutexClarinhoQueSim-XEDA2OKREMLIN campaign mutex
Customer ID98d8049e-804f-11f1-b79f-ae3a8bb85d01Identifier associated with the current campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/kremlin-banking-malware/