Malware Bypasses Browser Checks to Force Install Chrome, Edge Extensions
Bleeping Computer, Wednesday, September 16th, 2026
BleepingComputer reports that Elastic Security Labs found malware force-installing Chrome and Edge extensions by bypassing integrity checks.
BleepingComputer covers Elastic Security Labs research into KREMLIN, a toolkit that installs unapproved Chromium extensions by copying them straight into browser profile directories and rewriting the browser's security settings so they load as if the user had approved them.
Infection starts when a target opens a JavaScript file disguised as a banking document. The resulting extensions steal cookies, session tokens and keylogged passwords, take screenshots and intercept HTTP traffic.
Elastic ties the activity to a Brazilian actor running at least seven campaigns since May 2025 against 12 banks, confirming 1,515 infections.