News

Public · Published

Hackers Force-Installing Chrome Extensions That Steal Bank Passwords and Login Sessions: Report

KREMLIN banking malware forcefully installs malicious Chrome and Edge extensions that steal passwords and login sessions without user consent. Elastic Security Labs linked this Brazilian toolkit to seven campaigns since May 2025 and disrupted over 1,500 infections.

Published:

Updated:

What happened

KREMLIN banking malware forcefully installs malicious Chrome and Edge extensions that steal passwords and login sessions without user consent. Elastic Security Labs linked this Brazilian toolkit to seven campaigns since May 2025 and disrupted over 1,500 infections.

Confirmed

Global impact / market context

This malware can drain bank accounts by stealing login credentials, harming consumers and damaging trust in online banking. Financial firms may face higher fraud costs and need to boost security, potentially reducing profits per sale.

Analyst inference

Rising cyber threats often pressure companies to increase capital spending on security, raising costs. Banks and payment processors might see higher operational expenses, while cybersecurity firms could gain revenue from increased demand for protective services.

Analyst inference

What to watch

  1. Track Elastic Security Labs' reports on KREMLIN malware for new campaigns or changes in attack techniques, as they have already identified seven campaigns since May 2025. Confirmed
  2. Watch for regulatory responses from banking authorities that could force financial firms to adopt stricter security measures, potentially raising compliance costs and affecting their revenue. Proposed
  3. Monitor investment in cybersecurity companies that provide defense against such malware, as higher attack volumes could increase demand for their products and boost their sales. Analyst inference

Evidence