Introduction: The KREMLIN Threat and Modern Cybersecurity Data Breaches
As financial threat actors refine their tactics, browser-level compromises have become one of the most reliable paths into accounts, sessions, and ultimately corporate data. A banking malware operation active since mid-2025 illustrates this shift vividly: the group has been using a toolkit named KREMLIN to force-install malicious Chrome and Edge extensions, quietly bypassing the browser checks that ordinary users — and many enterprise controls — assume will stop unwanted installs. Dissected by Kaspersky and reported by BleepingComputer in September 2026, the campaign is a useful case study in how recent cybersecurity data breaches increasingly begin not with a network perimeter failure, but with a trusted, policy-installed browser extension that the user never agreed to.
The KREMLIN operation matters for more than its name. It shows how an established malware distribution chain — spam, malvertising, trojanized software — can be paired with a developer-facing Chromium feature to obtain a persistent, high-privilege foothold inside the two most popular enterprise browsers. For security teams tracking cyber attacks and data breach postmortems, the forced-extension technique is a template that other crime families are likely to copy.
Browser-Level Compromise in Contemporary Data Breach Case Studies
Browser extensions sit at an uncomfortable intersection: they are powerful, almost application-level software, yet they are installed, updated, and trusted through mechanisms most users treat like clicking a hyperlink. A malicious extension with broad host permissions can read and modify traffic on every site the victim visits, inject scripts into banking and webmail pages, capture form input, and exfiltrate credentials and session material — all while the address bar still shows a valid padlock.
This is why forced browser extension installs keep appearing in cybersecurity data breach case studies involving financial fraud. Once malware achieves extension-level access, the victim's browser effectively becomes attacker-controlled infrastructure. Two-factor prompts delivered through the browser, anti-phishing warnings, and even some enterprise DLP tooling can be undermined because the injected code runs inside the trusted rendering context rather than as an obvious external threat. The same theme — a trusted configuration or integration path becoming the breach vector — runs through high-profile incidents such as the SonicWall cloud backup compromise case study.
KREMLIN is notable because it removes the weakest link in that chain: the user's consent prompt.
The KREMLIN Toolkit and Its Delivery Chain
The operation has been active since mid-2025 and bundles several components under the KREMLIN label. The final payload is delivered through mainstream malware distribution chains: spam emails, malvertising, and trojanized software downloads. In other words, the initial access step is deliberately unremarkable — the toolkit's value is what happens after the dropper executes on a Windows machine.
According to Kaspersky's analysis, the malware's core is an injector called SSO Go, disguised under the guise of a login assistance tool. That naming is intentional mimicry: users conditioned to expect single sign-on helpers are less likely to question a program presenting itself that way. Once running, the injector's primary mission is to get a malicious extension into the victim's Chrome or Edge browser without ever triggering the install confirmation dialog that Chromium normally displays.
How Forced Extension Installation Bypasses Browser Checks
KREMLIN exploits the Chromium External Extensions Install protocol — a legitimate mechanism intended for enterprise software vendors to install companion extensions silently. The protocol works through browser preference entries that register an extension ID alongside an external install source (an update URL, path, or registry key). When the browser processes these entries, it installs or updates the extension automatically, as if an administrator had deployed it through policy.
KREMLIN abuses this by writing the appropriate preference entries directly, tricking Chrome and Edge into fetching and installing the attacker's extension with no user interaction. The tell is subtle: in the browser's extensions page, the entry is flagged as installed by "Enterprise policy install" (or the External Install protocol equivalent), with the install prompt disabled. A victim who never visits chrome://extensions will never see the badge; a victim who does may not recognize what the flag means.
Two defensive facts stand out from the technique:
- The install is legitimate-looking. The browser is not exploited; it is following its own policy logic. Malware that respects the intended API surface is harder for behavior-based detection to flag than code that exploits a memory corruption bug.
- The extension survives casual cleanup. Because policy-installed extensions cannot simply be removed from the extensions UI, users who notice the unwanted add-on often cannot uninstall it without locating and deleting the registry key or preference file that registered it — or resetting browser policy state entirely.
The same technique is available to both Chrome and Edge on Windows, since both are Chromium-based, which doubles the attack surface for a single code path.
Web Injection: The Payoff Behind the Forced Install
Once the extension is in place, KREMLIN shifts to its real objective: web injections into a broad list of financial and communication services. Kaspersky's researchers counted 77 targeted domains, spanning Russian banks, payment systems, crypto exchanges, foreign exchange services, international banks including UK and Turkish institutions, major webmail providers, and government websites.
The malware's designers believe their injection approach provides a decisive advantage over competing banking malware families: their flows require only one attack flow to successfully inject code, versus two flows required by other families. In practical terms, fewer steps mean a higher success rate per victim and a shorter window for the injection to fail or be noticed.
That efficiency pays off directly in credential-theft volume. KREMLIN also ships a module for stealing credentials from webmail services, showing overlays on top of legitimate login pages to harvest usernames and passwords. Compromised mailboxes then feed account-takeover chains — password resets, 2FA intercepts, and mailbox rules that suppress victim notifications — a pattern that recurs across recent cybersecurity data breaches that started as ordinary banking trojan infections.
Why Financial Threat Actors Are Converging on This Technique
For crime groups, forced extension installation offers an unusually attractive risk-to-reward profile. It reuses a supported Chromium feature rather than a zero-day, so there is no patch race. It lands privileges close to where money moves: sessions, tokens, and login forms. And it is portable — the same preference-manipulation logic works across Chrome and Edge, and the extension packages themselves are largely browser-agnostic.
The KREMLIN campaign also demonstrates the value of bundling. By pairing the SSO Go injector, the forced-install mechanism, a 77-domain web injection engine, and a webmail overlay stealer in one toolkit, the operators reduced dependence on multiple, separately maintained malware stacks. Toolkit consolidation like this tends to spread quickly in the cybercrime ecosystem, and browser-extension security teams should expect copycat implementations targeting other Chromium policy surfaces. It mirrors the broader pattern of attackers abusing mechanisms users are trained to trust, seen in social-engineering intrusions such as the Coupang data breach, where legitimate-looking authentication flows were turned against the victim organization.
Defensive Guidance for Organizations and Individuals
Organizations cannot rely on user prompts for extensions that policy mechanisms can suppress. Practical mitigations include:
- Audit browser policy state. Monitor the registry locations and preference files used by the External Extensions Install protocol on endpoints, and alert on entries created by non-approved processes.
- Inventory extensions continuously. Endpoint telemetry that lists every installed extension per browser profile will surface "Enterprise policy install" entries that no admin deployed.
- Constrain with real enterprise policy. Use Chrome/Edge administrative policies to restrict which extensions may install and from which sources, so attacker-supplied entries are rejected.
- Watch for injection behavior. Security controls that flag unexpected page modification or overlay windows on banking and webmail domains can catch the injection stage even when the install stage was missed.
For individuals, the guidance is narrower but still useful: periodically review chrome://extensions and edge://extensions for entries marked as installed by enterprise policy on personal machines, and treat unsolicited "login helper" or "SSO" software downloads as presumed malicious. Because removal of a policy-flagged extension from the UI is blocked, cleanup of an infected home machine typically requires reputable anti-malware scanning rather than manual uninstallation.
Conclusion: Hardening the Browser Before the Next Breach
The KREMLIN operation, active since mid-2025 and dissected publicly in 2026, is a reminder that the most consequential step in many recent cybersecurity data breaches is not the initial intrusion but the persistence layer chosen afterward. By forcing malicious Chrome and Edge extensions through a legitimate Chromium protocol, the operators gained invisible, durable, high-privilege access to banking and webmail sessions across 77 targeted domains. Defending against this class of threat means treating browser extension state as seriously as firewall rules and admin credentials — because for today's banking trojans, the browser is the attack surface. And as AI-assisted operations keep raising the pace of AI cybersecurity threats across the breach landscape, automated toolkits like KREMLIN are likely to be among the first techniques copycatted at scale.
Sources
- BleepingComputer: Malware bypasses browser checks to force install Chrome, Edge extensions (Bill Toulas, September 16, 2026), based on Kaspersky's analysis of the KREMLIN campaign.