Malware bypasses browser checks to force install Chrome and Edge extensions
Active since mid-2025, a banking malware operation is using the KREMLIN toolkit to install malicious browser extensions that steal sensitive data.

According to BleepingComputer, a banking malware operation active since mid-2025 has been leveraging a toolkit named KREMLIN to bypass security checks in modern web browsers.
The primary objective of this campaign is to force-install malicious extensions into Google Chrome and Microsoft Edge. Once deployed, these extensions are designed to harvest user credentials, session tokens, and other sensitive information.
The KREMLIN toolkit employs sophisticated methods to circumvent built-in browser security controls, posing a significant risk to everyday internet users. Such covert operations can remain undetected within a system for extended periods.
For tech audiences and users in Uzbekistan and the broader CIS region, this highlights the growing sophistication of modern cyber threats. Staying vigilant about browser extensions and online banking security is more crucial than ever.
As threat actors continue to find new ways to exploit browser architectures, both platform developers and security researchers must continuously adapt their defense mechanisms to protect end-users from stealthy malware campaigns.



