Executive Summary

The KREMLIN banking malware operation, active since mid-2025, has been deploying sophisticated techniques to bypass browser security mechanisms and forcibly install malicious Chrome and Edge extensions. The Brazilian-based threat actors use JavaScript files disguised as legitimate business documents to initiate infections, which then utilize Node.js persistence, Ethereum smart contracts for C2 communication, and advanced browser manipulation techniques. The malicious extensions, masquerading as AVSync, steal credentials, session tokens, and sensitive data while bypassing Chromium's integrity checks through cryptographic key manipulation. Elastic Security Labs confirmed 1,515 infected systems, primarily in Brazil, with the operation generating approximately $20,800 in cryptocurrency transactions. This campaign represents a significant evolution in banking malware tactics, demonstrating how threat actors are adapting to modern browser security controls while maintaining stealth and persistence across enterprise environments.

Why This Matters Now

Browser-based attacks are rapidly evolving with sophisticated bypass techniques targeting enterprise security controls, making traditional perimeter defenses insufficient against modern credential theft and session hijacking campaigns.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

KREMLIN retrieves browser encryption keys and regenerates cryptographic integrity checks (HMACs) to make malicious extensions appear legitimate to Chrome and Edge browsers.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the KREMLIN banking malware's ability to establish system-wide persistence and cross-browser lateral movement through segmented workload isolation. The attack's blast radius would likely be reduced by limiting east-west traffic flows and controlling outbound communication channels used for credential exfiltration.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The malware's ability to communicate with downstream infrastructure components would likely be constrained through segmented network paths and controlled service-to-service communication channels.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The malware's scope for system-wide persistence and cross-profile access would likely be reduced through identity-aware access controls and workload isolation boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-browser and cross-profile propagation would likely be constrained through restricted internal traffic flows and segmented communication paths between browser processes and system components.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The malware's ability to establish diverse external communication channels would likely be constrained through centralized visibility and policy enforcement across cloud service boundaries.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The volume and scope of sensitive data exfiltration would likely be reduced through controlled outbound traffic policies and restricted external communication channels.

Impact (Mitigations)

While banking account compromise may still occur through stolen credentials, the attacker's ability to maintain persistent access and expand operations would likely be constrained by reduced infrastructure reach.

Impact at a Glance

Affected Business Functions

  • Online Banking Services
  • Customer Account Management
  • Financial Transaction Processing
  • Digital Payment Systems
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Banking credentials, session tokens, cookies, local storage data, browsing history, form input including passwords, and sensitive financial information from 1,515 confirmed infected systems primarily in Brazil across 12 targeted banks

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized browser extension installations and limit malware persistence mechanisms
  • Deploy Egress Security & Policy Enforcement to block suspicious outbound connections to Ethereum smart contracts and unauthorized external domains used for C2 communications
  • Enable Multicloud Visibility & Control to detect anomalous browser automation, repeated malformed requests, and suspicious WebSocket connections indicative of malicious extension activity
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal browser behavior and alert on covert tools like unauthorized Node.js installations and extension manipulation
  • Utilize Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous detection of browser-based attacks and credential theft attempts targeting financial institutions

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image