Executive Summary
The KREMLIN banking malware operation, active since mid-2025, has been deploying sophisticated techniques to bypass browser security mechanisms and forcibly install malicious Chrome and Edge extensions. The Brazilian-based threat actors use JavaScript files disguised as legitimate business documents to initiate infections, which then utilize Node.js persistence, Ethereum smart contracts for C2 communication, and advanced browser manipulation techniques. The malicious extensions, masquerading as AVSync, steal credentials, session tokens, and sensitive data while bypassing Chromium's integrity checks through cryptographic key manipulation. Elastic Security Labs confirmed 1,515 infected systems, primarily in Brazil, with the operation generating approximately $20,800 in cryptocurrency transactions. This campaign represents a significant evolution in banking malware tactics, demonstrating how threat actors are adapting to modern browser security controls while maintaining stealth and persistence across enterprise environments.
Why This Matters Now
Browser-based attacks are rapidly evolving with sophisticated bypass techniques targeting enterprise security controls, making traditional perimeter defenses insufficient against modern credential theft and session hijacking campaigns.
Attack Path Analysis
The KREMLIN banking malware begins with a social engineering attack using fake financial documents to execute malicious JavaScript, then establishes persistence through scheduled tasks and Node.js installation. The malware bypasses browser integrity mechanisms to forcibly install credential-stealing extensions on Chrome and Edge without user consent. It maintains command and control through WebSocket connections and Ethereum smart contracts while continuously exfiltrating sensitive banking data, cookies, and credentials. The operation culminates in financial fraud through stolen session tokens and intercepted banking transactions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers distribute malicious JavaScript files disguised as bank receipts, invoices, and payment records that bypass anti-sandbox checks and execute initial payload
MITRE ATT&CK® Techniques
Spearphishing Attachment
Scheduled Task/Job: Scheduled Task
Process Injection
Browser Extensions
Steal Web Session Cookie
Input Capture: Keylogging
Screen Capture
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Deploy a change detection mechanism
Control ID: 11.6.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and classification of ICT risk
Control ID: Article 8
CISA ZTMM 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
NIS2 Directive – Risk analysis and information system security policies
Control ID: Article 21(2)(a)
GDPR – Security of processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
KREMLIN banking malware specifically targets financial institutions with credential theft extensions, bypassing browser security to steal banking sessions and sensitive financial data.
Financial Services
Browser extension malware compromises financial service platforms through keylogging, session hijacking, and data exfiltration, requiring enhanced egress security and anomaly detection.
Computer/Network Security
Security firms face advanced threats using documented but rare techniques to bypass Chromium integrity checks, demanding improved threat detection and response capabilities.
Information Technology/IT
IT organizations must implement zero trust segmentation and encrypted traffic monitoring to prevent malware lateral movement and protect against browser-based credential theft.
Sources
- Malware bypasses browser checks to force install Chrome, Edge extensionshttps://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/Verified
- KREMLIN Banking Malware - Elastic Security Labshttps://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malwareVerified
- The Phantom Extension: Backdooring Chrome through uncharted pathwayshttps://www.synacktiv.com/en/publications/the-phantom-extension-backdooring-chrome-through-uncharted-pathwaysVerified
- KREMLIN Malware IOCs - Elastic Labshttps://github.com/elastic/labs-releases/tree/main/indicators/kremlinVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the KREMLIN banking malware's ability to establish system-wide persistence and cross-browser lateral movement through segmented workload isolation. The attack's blast radius would likely be reduced by limiting east-west traffic flows and controlling outbound communication channels used for credential exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The malware's ability to communicate with downstream infrastructure components would likely be constrained through segmented network paths and controlled service-to-service communication channels.
Control: Zero Trust Segmentation
Mitigation: The malware's scope for system-wide persistence and cross-profile access would likely be reduced through identity-aware access controls and workload isolation boundaries.
Control: East-West Traffic Security
Mitigation: Cross-browser and cross-profile propagation would likely be constrained through restricted internal traffic flows and segmented communication paths between browser processes and system components.
Control: Multicloud Visibility & Control
Mitigation: The malware's ability to establish diverse external communication channels would likely be constrained through centralized visibility and policy enforcement across cloud service boundaries.
Control: Egress Security & Policy Enforcement
Mitigation: The volume and scope of sensitive data exfiltration would likely be reduced through controlled outbound traffic policies and restricted external communication channels.
While banking account compromise may still occur through stolen credentials, the attacker's ability to maintain persistent access and expand operations would likely be constrained by reduced infrastructure reach.
Impact at a Glance
Affected Business Functions
- Online Banking Services
- Customer Account Management
- Financial Transaction Processing
- Digital Payment Systems
Estimated downtime: N/A
Estimated loss: N/A
Banking credentials, session tokens, cookies, local storage data, browsing history, form input including passwords, and sensitive financial information from 1,515 confirmed infected systems primarily in Brazil across 12 targeted banks
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized browser extension installations and limit malware persistence mechanisms
- • Deploy Egress Security & Policy Enforcement to block suspicious outbound connections to Ethereum smart contracts and unauthorized external domains used for C2 communications
- • Enable Multicloud Visibility & Control to detect anomalous browser automation, repeated malformed requests, and suspicious WebSocket connections indicative of malicious extension activity
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal browser behavior and alert on covert tools like unauthorized Node.js installations and extension manipulation
- • Utilize Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous detection of browser-based attacks and credential theft attempts targeting financial institutions



