A malicious software known as KREMLIN has been discovered to install a pirated extension on Chrome and Edge browsers by bypassing security checks built into the Chromium platform. Once installed, this malware can extract sensitive data such as cookies, passwords, and session tokens from the victim’s browser. The infection typically begins when a user opens a seemingly legitimate document—such as a fake bank receipt or invoice—containing a JavaScript file. When executed, this file initiates a chain of actions that install the KREMLIN extension directly into the browser, without going through the official Chrome Web Store. The malware first checks if it is being run in a simulated or analysis environment, which attackers often use to detect and study threats. If it detects such an environment, it halts execution to avoid detection. Otherwise, it proceeds to download a Node.js environment and a C++ program, which then loads the main malicious payload. This payload is signed with a certificate from the security company SentinelOne, making it appear legitimate. The malware then regenerates cryptographic hashes used by Chromium to verify the integrity of browser extensions, effectively allowing it to install itself without triggering alerts. KREMLIN has been active for over fifteen months and has been linked to seven different campaigns. It was discovered and tracked by Elastic Security Labs, which noted that the malware has been used by the Chinese APT31 group in a similar attack that exploited the same integrity bypass. The extension connects to a remote command server through a WebSocket channel and regularly checks for instructions. These commands can include taking screenshots, stealing cookies, or injecting malicious HTML code into web pages. The malware also communicates with a second endpoint disguised as a CSS file request, where each path corresponds to a specific function, such as retrieving browsing history or intercepting form data on payment pages. The KREMLIN malware is designed to mimic Brazilian banks, including Banco do Brasil and Santander, and uses Portuguese in its error messages and code comments. Despite its name, which suggests a Russian origin, no confirmed link to Russia has been established. An Ethereum wallet associated with the malware’s deployment recorded over 80 transactions between 2025 and 2026, with activity matching office hours in São Paulo, Brazil. Researchers have taken steps to slow down the malware’s spread by registering a domain it checks before executing. Over 1,500 infected systems have attempted to connect to this domain, with most located in Brazil. Experts recommend users regularly check their installed browser extensions and disable Chrome’s developer mode when not needed to detect unauthorized additions.