:

BANKING MALWARE FORCES MALICIOUS EXTENSIONS

SECURITY DESK1 MIN READ
WED, SEP 16, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A banking malware operation has been deploying a toolkit called KREMLIN since mid-2025 to bypass browser security checks and force-install malicious extensions on Chrome and Edge browsers. The extensions target user credentials and session tokens.

The KREMLIN toolkit circumvents standard browser installation protections to inject extensions without user consent. Once installed, the malicious extensions steal banking credentials, session tokens, and other sensitive data from infected systems. The operation specifically targets Chrome and Microsoft Edge, two of the most widely-used browsers globally. The malware's ability to bypass browser-level security measures suggests sophisticated engineering designed to evade both user detection and security software. Affected users may experience unauthorized access to financial accounts and compromised login sessions. The threat underscores the importance of keeping browsers updated and avoiding suspicious downloads. Security researchers are tracking the operation and working with browser vendors on detection methods. Users should monitor browser extensions for unfamiliar additions and consider using security tools that monitor unauthorized installations.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The ShinyHunters hacking group has published thousands of drivers' personal records after breaching Florida's motor vehicle database. The leak follows the gang's failed ransom demand to the state agency.

JUST NOWSecurity Desk

Data broker Radaris.com has lost its domains after a New Jersey court ruling in a privacy violation case. The company faced legal action for publishing personal information on state law enforcement officials in violation of state privacy law.

JUST NOWAI Desk

Spain's data protection agency has received its first report of a cyberattack carried out using an AI agent powered by a large language model. The breach marks a new category of security threat for regulators.

1H AGOAI Desk

Security researchers have identified a new wave of dating app scams leveraging AI to create fraudulent profiles and fake video calls designed to deceive users into sending money.

4H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.