KREMLIN Malware: A New Threat That Bypasses Browser Defenses
According to a recent report from The Hacker News, security researchers have uncovered a banking malware operation known as KREMLIN. This malware specifically targets Google Chrome and Microsoft Edge users by installing a malicious browser extension that steals login credentials and session tokens.
What makes this attack noteworthy is how it bypasses Chrome’s built-in security protections. The malware manipulates browser configuration files to force-install the extension without triggering warnings. It also uses Ethereum blockchain smart contracts to hide its command-and-control servers, making it much harder for security teams to shut down.
Why This Malware Matters Beyond Brazil
Although KREMLIN currently targets Brazilian banks, the techniques used here can easily be adapted to target Australian financial institutions or any online service. The key danger is session token theft—if a criminal steals your active login session, they can access your accounts without needing your password or two-factor authentication codes.
For Australian small and mid-sized businesses, this should be a wake-up call. Many SMBs rely on browser-based tools for banking, accounting, and customer management. A single infected computer could give attackers access to company financial accounts, client data, and internal systems. The use of blockchain to hide command servers also means that traditional blocking methods are less effective.
What This Means for Australian SMBs
Australian businesses often think cybercriminals only target large corporations or US-based companies. But malware like KREMLIN shows that attackers are becoming more sophisticated and can repurpose their tools for any target. If a Brazilian banking trojan can infect systems in Brazil, similar code can be modified to target Australian banking portals or cloud services commonly used by SMBs.
Because this malware spreads through fake invoices and documents, your employees are the first line of defense. A single click on a malicious file could lead to a full compromise of your browser sessions and sensitive data. The risk is especially high for businesses that allow staff to use personal devices or unmanaged browsers for work tasks.
What You Can Do Now
- Enable browser security policies that block extension installations from outside the official Chrome Web Store. Use group policies for managed devices.
- Educate staff to never open unexpected invoices or documents from unknown senders. Verify urgent requests via a separate communication channel.
- Implement endpoint detection and response (EDR) tools that can spot unusual browser behavior, such as unauthorized extension loading or anomalous network connections.
- Use multi-factor authentication (MFA) that does not rely on browser sessions alone—for example, app-based authenticators or hardware security keys.
- Regularly audit installed browser extensions on company devices and remove any that are not explicitly approved by IT.
For Australian SMBs looking to strengthen their defences against evolving threats like KREMLIN, MS&VG can help assess your current browser security posture and recommend tailored solutions to protect your business data.