News
Public · Published
Hackers Force-Installing Chrome Extensions That Steal Bank Passwords and Login Sessions: Report
KREMLIN banking malware forcefully installs malicious Chrome and Edge extensions that steal passwords and login sessions without user consent. Elastic Security Labs linked this Brazilian toolkit to seven campaigns since May 2025 and disrupted over 1,500 infections.
Published:
Updated:
What happened
KREMLIN banking malware forcefully installs malicious Chrome and Edge extensions that steal passwords and login sessions without user consent. Elastic Security Labs linked this Brazilian toolkit to seven campaigns since May 2025 and disrupted over 1,500 infections.
Confirmed
Global impact / market context
This malware can drain bank accounts by stealing login credentials, harming consumers and damaging trust in online banking. Financial firms may face higher fraud costs and need to boost security, potentially reducing profits per sale.
Analyst inference
Rising cyber threats often pressure companies to increase capital spending on security, raising costs. Banks and payment processors might see higher operational expenses, while cybersecurity firms could gain revenue from increased demand for protective services.
Analyst inference
What to watch
- Track Elastic Security Labs' reports on KREMLIN malware for new campaigns or changes in attack techniques, as they have already identified seven campaigns since May 2025. Confirmed
- Watch for regulatory responses from banking authorities that could force financial firms to adopt stricter security measures, potentially raising compliance costs and affecting their revenue. Proposed
- Monitor investment in cybersecurity companies that provide defense against such malware, as higher attack volumes could increase demand for their products and boost their sales. Analyst inference