SICHERHEIT & DATENSCHUTZ

New malware installs harmful browser extensions

New malware installs harmful browser extensions

A new banking malware uses KREMLIN to install harmful extensions in Chrome and Edge to steal data.

A new threat in the field of cybercrime has emerged since mid-2025. A banking malware operation known as KREMLIN has managed to bypass security measures in common web browsers. This malware installs malicious extensions for Google Chrome and Microsoft Edge that aim to steal sensitive data from users.

The KREMLIN malware employs a sophisticated technique to circumvent browser checks. This allows cybercriminals to install their malicious extensions unnoticed. These extensions are programmed to capture login credentials, session tokens, and other confidential information necessary for accessing online banking and other sensitive services.

How the Malware Works

The malware is typically spread through phishing emails or compromised websites. Once a user clicks on a malicious link or downloads an infected file, the KREMLIN software is activated. This software can then request the necessary permissions to install the malicious extensions without the user noticing.

Once installed, the extensions can operate in the background and collect data while the user continues to browse the internet. The collected information is then transmitted to the attackers, who can use it for fraudulent activities. This poses a significant risk to user security, especially for those who use online banking services.

The malware has proven to be particularly dangerous as it not only steals data but also provides the ability to take control of the affected accounts. The attackers can then carry out transactions or install further malicious software on the victims' devices.

Protective Measures and Responses

The security community has responded to the threat posed by KREMLIN by developing new detection methods and protective measures. Companies and organizations are encouraged to review their security protocols and ensure that their systems are equipped to defend against such attacks. Regular training for employees on recognizing phishing attempts is also crucial.

Users are urged to be cautious with links and attachments in emails and to regularly check their browsers for suspicious extensions. Removing unknown or unused extensions can help reduce the risk of infection. Security researchers continue to analyze the methods of the malware and develop effective countermeasures.

The KREMLIN malware is an example of the ever-evolving threats in the field of cybercrime. Attackers are using increasingly sophisticated techniques to achieve their goals, highlighting the need for continuous vigilance and adaptation of security strategies.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen