A sophisticated banking malware campaign has escalated its tactics, using a specialized toolkit to bypass built-in browser security controls and silently force the installation of malicious extensions in Chrome and Microsoft Edge. According to research reported by BleepingComputer, the operation—active since at least mid-2025—leverages a toolkit dubbed KREMLIN to hijack user sessions and exfiltrate high-value data, posing a significant threat to corporate environments.
The core innovation of the KREMLIN toolkit lies in its method of infection. Instead of relying on traditional social engineering to trick users into manually installing a rogue extension, it manipulates internal browser verification and update mechanisms. By faking legitimate system processes, the malware achieves installation without requiring any user consent or interaction. This marks a critical shift from deceptive tactics to a technical bypass of the user consent safeguard, operating with what appears to be legitimate authority.
Once installed, these malicious extensions are designed for comprehensive data theft. They harvest credentials, session tokens, cookies, and form data from compromised browsers. The theft of session tokens is particularly perilous for enterprises, as it allows attackers to hijack active, authenticated sessions. This can lead directly to unauthorized access to internal financial systems, cloud portals, and email accounts, bypassing standard login procedures entirely. The stolen data then facilitates persistent access, lateral movement within a network, and data exfiltration, all while evading detection by blending with normal browsing activity.
The emergence of a dedicated toolkit like KREMLIN suggests this is not an isolated attack but part of a scalable, modular criminal infrastructure. Security teams should anticipate the proliferation of copycat variants leveraging similar browser-level bypass techniques. This elevates the threat from a simple credential-stealer to a potential platform for broader corporate network compromise.
Actionable Defensive Guidance for IT and Security Teams
Given that traditional user awareness training is insufficient against this technical bypass, defense must pivot to centralized controls and enhanced monitoring. IT teams managing fleets of Chrome and Edge browsers should prioritize the following:
- Centralized Extension Whitelisting: Enforce strict policies via group policies or MDM solutions to allow only approved, known-safe extensions. Block the installation of new extensions by default.
- Endpoint Detection & Response (EDR) Tuning: Configure EDR solutions to monitor for suspicious events related to browser extension installation and activity. Alert on extensions that attempt to access browsing history, clipboard data, or make unusual network connections.
- Network Traffic Monitoring: Deploy network analysis tools to identify and block connections from browser extensions to known malicious command-and-control servers.
- Browser Policy Hardening: Disable auto-update features for extensions where possible and use managed browser profiles to apply security settings at scale.
- Vigilance on Initial Access Vectors: While the KREMLIN bypass handles installation, the initial delivery of the malware toolkit to a system likely still requires a phishing link, malicious download, or exploit. Reinforce email filtering and endpoint protection.
Enterprise organizations, particularly those with high-value assets in corporate finance systems, should treat this as a high-priority concern. The combination of silent installation, credential theft, and session hijacking creates a potent attack chain capable of bypassing many conventional security layers. Proactive, policy-driven defense is now essential.
一個複雜的銀行惡意軟件活動已升級其策略,使用專門的工具組繞過瀏覽器內建的安全控制機制,並強制靜默安裝惡意的 Chrome 及 Microsoft Edge 擴充功能。根據 BleepingComputer 報導的研究,這項至少自 2025 年中開始運作的活動,利用名為 KREMLIN 的工具組來劫持用戶會話並竊取高價值數據,對企業環境構成重大威脅。
KREMLIN 工具組的核心創新在於其感染方式。它並非依賴傳統的社會工程學來誘騙用戶手動安裝流氓擴充功能,而是操控瀏覽器內部的驗證與更新機制。透過偽裝成合法的系統程序,該惡意軟件得以在無需任何用戶同意或互動的情況下完成安裝。這標誌著從欺騙策略到技術性繞過用戶同意保障機制的重大轉變,其運作彷彿擁有合法權限。
一旦安裝,這些惡意擴充功能旨在進行全面的數據竊取。它們會從受感染的瀏覽器中竊取憑證、會話代幣、Cookies 和表單數據。會話代幣的竊取對企業尤其危險,因為攻擊者可藉此劫持活躍的、已驗證的會話。這可能直接導致未經授權訪問內部財務系統、雲端門戶和電子郵件帳戶,完全繞過標準的登入程序。被竊的數據隨後有助於維持持久訪問權限、在網絡內進行橫向移動及數據外洩,同時透過與正常瀏覽活動混雜來規避偵測。
像 KREMLIN 這樣專用工具組的出現,表明這並非孤立的攻擊,而是可擴展、模組化的犯罪基礎設施的一部分。安全團隊應預期會有更多利用類似瀏覽器層級繞過技術的仿冒變種出現。這將威脅從簡單的憑證竊取器,提升為可能更廣泛地入侵企業網絡的平台。
IT 與安全團隊的可行防禦指引
鑑於傳統的用戶意識培訓不足以應對此技術性繞過,防禦重心必須轉向集中控制與加強監控。管理 Chrome 和 Edge 瀏覽器機群的 IT 團隊應優先考慮以下措施:
- 集中式擴充功能白名單: 透過群組原則或 MDM 方案強制執行嚴格政策,僅允許已批准、已知安全的擴充功能。預設阻止安裝新擴充功能。
- 端點偵測與回應(EDR)調校: 設定 EDR 方案以監控與瀏覽器擴充功能安裝及活動相關的可疑事件。對試圖存取瀏覽紀錄、剪貼簿數據或發起異常網絡連線的擴充功能發出警報。
- 網絡流量監控: 部署網絡分析工具,以識別並阻斷瀏覽器擴充功能連線至已知惡意指揮與控制伺服器的連線。
- 瀏覽器政策強化: 盡可能停用擴充功能的自動更新功能,並使用受管理的瀏覽器配置文件以大規模套用安全設定。
- 警惕初始訪問向量: 儘管 KREMLIN 繞過機制處理了安裝環節,但惡意軟件工具組最初的傳遞仍可能依賴釣魚連結、惡意下載或漏洞利用。應加強電子郵件過濾與端點防護。
擁有高價值資產(尤其是在企業財務系統方面)的企業組織,應將此視為高度優先的關注事項。靜默安裝、憑證竊取與會話劫持的結合,構成了一條強大的攻擊鏈,足以繞過許多傳統安全層級。主動的、基於政策的防禦現已至關重要。
