# Bypassing Chrome & Edge's integrity checking mechanism: Technical analysis of KREMLIN banking malware

## Campaign Summary

What will happen if a malicious code can arbitrarily load an extension into Chrome or Edge but the browser still believes that it is the standard configuration of the system? The KREMLIN (REF9334) banking malware campaign has just done the seemingly impossible: recalculating Chromium's internal HMAC signature to bypass all integrity checking mechanisms without emitting any security warnings.

Not stopping there, instead of wasting time trying to figure out passwords or OTP codes, KREMLIN attacks directly into the "blind spot" after authentication: extracting the masterkey from RAM memory to hijack a live Session Cookie, helping attackers automatically go through two-factor authentication (MFA) layers. More dangerously, the entire C2 infrastructure of the malicious code is also hidden on the Ethereum Blockchain, making all efforts to block IP or traditional domain names ineffective.

How can a malicious code running normal user rights bypass Google's latest App-Bound Encryption protection layer? How does an attacker create a byte-accurate fake HMAC string? Technical details of attack chain extraction and hidden detection process will be analyzed in depth in the next sections.

## Campaign Development Timeline

| **Timeline** | **Technical Event** |
| --- | --- |
| **05/2025** | The first KREMLIN samples were observed in Brazil, targeting users through phishing emails disguised as financial invoices. |
| **08/2025 – 02/2026** | The malware evolved with modules designed to bypass Chrome’s newer App-Bound Encryption protections and shifted its C2 infrastructure toward Ethereum Smart Contracts. |
| **09/2026** | Elastic Security Labs published a comprehensive analysis of REF9334, confirming KREMLIN’s ability to forge HMAC integrity values in Chrome’s `Secure Preferences`. |

## Attack Chain Analysis

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/6d81ed55-3933-483a-8f70-f7a364aaf200.png align="center")

### STEP 1: Initial Access

Initially, the attacker will send an email pretending to be a tax authority or payment invoice sending partner, attaching a compressed file (.zip) or JavaScript file (.js).

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/d3d02807-dd60-4278-99c5-016abcdf4520.png align="center")

When the curious victim clicks to open the file, the code hidden inside immediately runs in the background under the user account without displaying any interface on the screen.

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/32b74be7-e7ff-46bb-8e7d-aaeb9e2a0b58.png align="center")

### STEP 2: Environmental testing (Anti-Analysis & Staging)

After running in the background, the malicious code will download a test module (Loader) to ask itself: "Is this the victim's real machine or the virtual machine/sandbox of the security expert who is analyzing?"

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/cb76cecb-ee4d-4ffa-9482-a5ee3c5982cf.png align="center")

How it works:

*   If anti-virus software or virtual machine processes (VMware, VirtualBox) are detected, the malicious code will commit suicide or remain inactive to avoid detection.
    
*   If it confirms that it is a real machine, it will continue to download the main malicious module.
    

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/d59958e1-27d1-4e4b-bbcf-186f219c0dce.png align="center")

### STEP 3: Browser Hack & HMAC Signature Forgery (Defense Evasion)

*This is KREMLIN's most unique and dangerous technique.*

Chrome/Edge problem: Browsers save Extension settings information in the Secure Preferences file. To avoid malicious code inserting extensions, Chrome calculates an authentication code (HMAC hash) based on the computer hardware. If this code is incorrect, Chrome will disable the Extension and display a red warning.

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/3d539b4c-ea65-4132-b922-d16474cf5716.png align="center")

How KREMLIN surpassed:

1.  The malicious code reads hardware information and victim account SID.
    
2.  It automatically recalculates the exact HMAC string according to Chromium's algorithm.
    
3.  Overwrite the malicious Extension with fake HMAC string into the Secure Preferences file.
    

Result: Chrome/Edge opens and believes that this malicious extension is "genuine product created by the browser itself", and does not issue a warning at all.

### STEP 4: Decryption keychain in RAM memory (App-Bound Encryption Bypass)

Chrome's problem: Chrome protects passwords and Cookies using the App-Bound Encryption mechanism (only system services with SYSTEM permissions are allowed to decrypt data files on the hard disk).

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/7142169d-a7c0-4f61-bd65-4620822eee9a.png align="center")

How KREMLIN circumvents the law:

1.  The malicious code does not bother decrypting files on the hard disk. It automatically launches a background Chrome process with the Debug parameter: chrome.exe --no-startup-window --remote-debugging-port=9222
    
2.  When Chrome launches in the background, Chrome's SYSTEM service will automatically decrypt the masterkey into RAM for the browser to use.
    
3.  KREMLIN attaches a debugger that hooks the decrypted masterkey directly from RAM.
    

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/7f622f05-b6ea-4f7e-a12f-cc18711e6d73.png align="center")

Result: The malicious code gets the entire decryption key without touching Windows' hard disk protection mechanism.

### STEP 5: Call C2 server via Ethereum Blockchain (Dead-Drop Resolver)

What will the attacker do at this stage? Of course they will need a server IP address (C2) to send data back, but if the IP/Domain is hardcoded, it is very easy to be blocked by security companies (Block/Sinkhole).

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/3365b000-8021-45f3-ac89-8a69b65d69f2.png align="center")

And from there, KREMLIN will solve the problem by:

*   The malicious code sends a valid query to the public nodes of the Ethereum Blockchain network.
    
*   The data returned from Smart Contract on Ethereum contains the actual encrypted C2 IP address.
    

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/7b0cc98c-c9e9-4c7f-aaec-d88cd0d0b81a.png align="center")

Result: Hackers who want to change the C2 server only need to make 1 transaction on the Blockchain. The C2 domain cannot be blocked by security because it is located on the decentralized Ethereum network.

### STEP 6: Session Cookie Theft & Bank Transaction Interference (Fraud & Exfiltration)

Session Cookie Theft (Bypass MFA): Malicious extension collects all Session Cookies logged in the browser and sends them to hackers. Hackers just need to load this Cookie into their device to log directly into the victim's bank/email account without needing a password or OTP code.

Real-time intervention (WebInject): When the victim transfers money on e-banking, the malicious Extension automatically inserts JavaScript code to change the beneficiary account number on the interface without the victim's knowledge.

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/8eeea2e3-eaec-43f9-81b2-7558d0f7e57b.png align="center")

**To summarize in an easy-to-remember way:**

*"KREMLIN tricks your computer into running malicious files, fakes Chrome's signature to install Extensions, steals security keys from RAM, hides server addresses on the Ethereum Blockchain and silently reuses your Cookies to withdraw money without needing a password or OTP."*

## Summary of Consequences

### For Businesses & Organizations

*   Direct financial loss: An attacker with real-time intervention (Real-time WebInject) changes the beneficiary account number when a business makes a money transfer order, or silently creates an unauthorized money transfer order.
    
*   Completely disable 2-layer authentication (MFA Bypass): By directly appropriating the active Session Cookie, hackers log in directly to internal systems (Webmail, ERP, Cloud Admin) without having to go through the step of entering a password or OTP code.
    
*   Loss of intellectual property & customer data: Gaining access to business information portals, collecting all transaction data and sensitive information.
    

### For Individual Users

*   Withdraw all money from bank account: Loss of control over all e-banking sessions and e-wallets open in the browser.
    
*   Identity Theft: Fraudsters can impersonate the victim to commit further fraudulent acts using the same stolen account/login session.
    

## **MITRE ATT&CK Mapping**

| **Tactic** | **Technique ID** | **Technique Name** | **Description of Application in KREMLIN** |
| --- | --- | --- | --- |
| **Initial Access** | `T1566.001` | Phishing: Spearphishing Attachment | Distributes JS/ZIP files disguised as financial invoices through phishing emails. |
| **Execution** | `T1059.007` | Command and Scripting Interpreter: JavaScript | Executes malicious JavaScript code as the initial loader on the victim’s system. |
| **Defense Evasion** | `T1562.001` | Impair Defenses: Disable or Modify Tools | Recalculates HMAC values to spoof the integrity of the browser’s `Secure Preferences` file. |
| **Defense Evasion** | `T1055` | Process Injection | Attaches a debugger and injects code into `chrome.exe` to bypass App-Bound Encryption protections. |
| **Persistence** | `T1176` | Browser Extensions | Forces a malicious browser extension to be loaded and maintained within the victim’s browser environment. |
| **Credential Access** | `T1555.003` | Credentials from Web Browsers | Extracts the OSCrypt master key from memory to decrypt and access cookies and session tokens. |
| **Command and Control** | `T1102.001` | Web Service: Dead Drop Resolver | Uses an Ethereum Smart Contract to dynamically retrieve C2 infrastructure information, such as C2 IP addresses or URLs. |

## **IOCs & Artifacts**

### **Domain**

*   acrobat-updater\[.\]com
    
*   codecaudiog\[.\]site
    
*   codecvideowin\[.\]online
    
*   cremeb\[.\]com
    
*   donalurdesconfeitos\[.\]site
    
*   harialurdes\[.\]site
    
*   marialurdes\[.\]site
    
*   lojinhadoluiz\[.\]online
    
*   mysterylink\[.\]xyz
    
*   quirkyclub\[.\]club
    
*   cheapzone\[.\]space
    
*   affordableonline\[.\]online
    
*   granderevolucao\[.\]store
    
*   connection.upgradeonline\[.\]site
    
*   seguranca.versionnova\[.\]site
    
*   volmira\[.\]site zaviro\[.\]online
    
*   version.checkeligibitily\[.\]workers\[.\]dev
    
*   orange-sun-195a.checkeligibitily\[.\]workers\[.\]dev
    

### IP:Port (C2)

*   185.221.23\[.\]133 :4782
    
*   144.172.112\[.\]239 :4782
    
*   45.90.13\[.\]210 :443
    
*   37.16.74\[.\]100 :443
    
*   37.16.74\[.\]34 :443
    
*   178.92.162\[.\]38 :443
    

### Host artifacts

*   File
    
    *   %APPDATA%\\57c88f0e6004.dat %APPDATA%\\dfa65addc8b6.dat
        
    *   %PUBLIC%\\Downloads\\Kremlin-JS-Updater-Trigger.js
        
    *   %PUBLIC%\\Downloads\\chromakey.js %TEMP%\\92f1a44d.ps1
        
    *   %TEMP%\\codec.js C:\\Users\\Public\\Downloads\\AcrobatWorker.js
        
    *   <cwd>\\SentinelAgentCore.dll
        
    *   <cwd>\\SentinelMemoryScanner.exe
        
*   Mutex (Global\\ và Local\\)
    
    *   540ca02e-fe15-4bef-a96e-9a5fbcfd8b4f
        
    *   ClarinhoQueSim-XEDA2O
        
*   Registry
    
    *   HKCU\\Environment\\KRL\_L\_FP
        
    *   HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Environment\\KRL\_L\_FP
        
    *   HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\6ba9d9e584a1
        
*   SHA 256
    
    *   `05aa4dc2904389b3c04ada0877de10a0152626527cb5f0b1d09aee5bcb25d6c2`
        
    *   `9070954d9b9760669d043c22d64316344567cbe4ba560d10dc1651413bde6d2d`
        
    *   `806c4c73f6951779ad76ea211b07dc9cc8be656a29e857a0f4edc7470df90c6d`
        
    *   `e51f7a4fa771c142d181148f31e8293de06dd8552ee37520dbff16b83d440cba`
        
    *   `19de1ed97916361097eccd70b921f4adce8de8b8c28881c38e8479864df130df`
        
    *   `5df7a18c5674abbab89a53d3398c3398b800b14f8ff08488d89407402325f75a`
        
    *   `2a15e72d46b620cbcb16ab968e478fcd29b5aa795faaa3b634814fa304ce80d5`
        
    *   `941591b7055eb7a569c377b6b90ea953ed350deb4de451d76fb8e54c91cc5197`
        
    *   `4a968220a54ea48266f795fa7de5575aaa63f21e73cd85191bb64a951d504001`
        
    *   `fabe10bb059c1c6c73d9674d247eefb3bfce9b7c42f4fe38b29b822b6830224e`
        
    *   `839b2ecc4485a55efc4fbbfd21f3ce609592d951147c0967c80bedd5eb65ca3b`
        
    *   `52be1b46357e5c6087848129fe8291086cff8a549a536d120269f8db3ad87eec`
        
    *   `e7b068e7ee327267ffe933163ffe1e57441a9839702989312b6ac0bd23aaafd2`
        
    *   `12a2974fe4af869fefb66886b4a2a6f34d358a54038c3424635fee5e5fae111e`
        
    *   `64310455d83296647b709ee7c9b048518a6a8ccedc90818827f77c91f406d8b6`
        
    *   `598764b174f35ca76586bd0036a3caf87538aec52a1f95cf1c4ce25e027cf71f`
        
    *   `35c598d4c0523b823245c314a3fef30dcacd04e2b00632b17bbd6ef4486b9d17`
        
    *   `475e5acc035b612e30a494fe89dd69c6ddd21da433528796ab372c8741c7ebd5`
        
    *   `bb0a89d0f7702e6eb0a9c97062b9bccf580bae5090708be09fa66decb5b48c3f`
        
    *   `f1b7f10e1ac61c516f192f32eec5a6b429c7e1cb91f660536380c1403416afb5`
        
    *   `157246a891eac27b00def96999f6878352d1d377cd8d66bf016b3b566722b108`
        
    *   `0553ef3338bf99f17c185706381ee546989fc2dedae627ef222b3d50befbe9d5`
        
    *   `b9ca09bfe7b4984673f5950d56b1ef1fcc5e1791accbe4dc6a45f579a92866a8`
        
    *   `c01d391b144dae2cca49b369f00966448497e89970283f185ce3a7221409ad44`
        
    *   `d154a0f1ccd39f519b1f70a62c667eb7101cd4577a0cdccd941e0f7a0ed42f81`
        
    *   `19be0e7a02ad953b3a17747b95df85d1f862d793abe3b14c06f0f09c0ac7b761`
        
    *   `6f08cb43e4d3492d3696dbd88508a9b9447cb9253598cdc9e8f1c347f96d3193`
        
    *   `17c60e17d75348b055687d1ad4f66c8b12f593f68952b6de5ab181c2b7905a6c`
        
    *   `b0cd9c56a74beb14a035c3b4617ac93abd387badcedd6fc9804b7f37f6a239b5`
        
    *   `3dbed386eb650cec405f862c7400498dd8e9deccf34e35e06c3235408a9da211`
        
    *   `f0270ecb5a6c888bab89e71b763039403c30c47605705ed4640b14751da141e7`
        
    *   `a27c8f54063297c2c958e05e7f97759cf099cf63bf6fc7b68098e412166a635a`
        
    *   `75d5e6bba3672f8e14509ae1c3eccf41986f40feb749279a79d3d791920bf2aa`
        
    *   `3e10724585ae86c92b7504014a540d3a97003c7120151db479445b0bc25b01d3`
        
    *   `de5ddf293b2218028988593a61ac8d5faf11605dc0f616c9a2e4858c127f8775`
        
    *   `2a45e65d67e3e6a40c91115a5a9d0ab482f88b206735e1391a351d376d0934f2`
        
    *   `e582390605a848286e4340ad14f4b075abeefdfe11e747f3e879967f7fad744a`
        
    *   `5c57c0caeb91dc7de7be8dd25b3163d48888d6305c402095b065e55c2cbdb7fc`
        
    *   `e767fda52cf4b0cc00774c7881c8827809b321bce6c9648428d804227ad35725`
        
    *   `eb38d4b51bc06b32933f700ba0ce350dde299984c7ec32fef4e84ca5673266b9`
        
    *   `aa4b1a5df8537ed754a4ecc1d0405d11c1c2d732833aabdbb7c138dcc8396f77`
        
    *   `62e0383b93de31204574ab52d136c58469e710ce38d2d7f061438ab5abbd76f7`
        
    *   `e896917d89f1932d4b59fcb1ac5b33928d9a844e74e7bc8737662a287e2c3110`
        
    *   `f3e081a4b2e4302d3b14e5f16aca269ea93aa5cb816bb7ac2a8e4f51a80f0fde`
        
    *   `7228abe11344f4465a7de1843808d01049dd16391ad4c73d96761368f2744fac`
        
    *   `daf3e772965618d02b05fea769c075f3a05c67ae0d40c308639098b8ce98d207`
        
    *   `eca724661d7fc6ad3db6aa00764ec39ecf3b996d3dcf74dc9f911b488f07ebe1`
        
    *   `aae44c43ee2a68004183446e395228d357dc34e4ae267d4f991afb8ef7622754`
        
    *   `f1660dd0d9b5bcf29efe5b4f98fdfc621b576cdd2e9a84528b32b9aeb5ef8243`
        
    *   `b6b0b98f2908b5d1d9865ff44d69bdb06871f5bd6ce7586a6e23ad4984671bcd`
        
    *   `ae083103985c7ecb2c7347d7c51b2ec324e95660aa6967376ccaa9240365222f`
        
    *   `f784fc9cc563519714293fe7894dd8430e00ab116ef44457e345316f12688541`
        
    *   `561376e9ca1b271f8382cadf76c3cfdf6dbe891ef675702f07f10b45dc8743fb`
        
    *   `6d30ae4fc97f8b3cbd0792458681fe9acf7881ff62ae63dd456b00047794446e`
        
    *   `4a5c12d6cdde0bf77ac86927c5ab17148bb1d96e822666c2a9952813b2c9bd67`
        
    *   `5569f1c7696adcbc9126d2c1bb68016eb2f84373323f03a5d46d142ce3db76ea`
        
    *   `0b05986986083f060f8b3138711c64378e88fc3b2378caeaf8c50d6229848b22`
        
    *   `734a5fe9a498f18c92b8d164d9d34e4df33b58e7db96ac23ed118799d1fb6476`
        
    *   `c4687ceddec1b3a20abfb44396287adf3495703ae0071f9ac56f86f1edbd2415`
        
    *   `4f9e745cf4cf2f2bb4caff03d658b86c2478e45fdf91f07bdbd357d339fd2448`
        
    *   `bc7d85e4d70c2b945723344d0d6d45b16c0b20be6e8c1fede289418cee19702b`
        
    *   `b7b6b51ba3aa9ce9e31e7cfa2e385d50bc58dd37527cf4cb29814268d1580a4b`
        
    *   `f916a1d470af760966715fb1abe195516b79612ff0c25f0a9e90c73fc89fdb96`
        
    *   `7b50c05689758989b178d958bf2bd6934cb8a9f0f696f81262e9258f3f0de07b`
        
    *   `08d0a3ec031091a2ee44f305a9e5172364f5ff55312a326b90f1c9f149ec1c11`
        
    *   `21ab843d95280d906de7d403f2aa8b6ede4cb10761b6878d99d3fe0213590005`
        
    *   `9c1facf582b1aff734eb330d479a37fa6e34a9f727f18aa94c5f09c550696a9e`
        
    *   `6ed344cfb855778b472b579f7337f1cfe15a64a6f6af82473c45e3fd0b42826e`
        
    *   `fe1a6826743d7a9a6a9f09ddc5c1d41da3d938fcc15f2df7f86ef384f29ab719`
        
    *   `9c583d16904613de786b1c4718a4c4b39ca1b16eb716f9622243e00e07d9a83f`
        
    *   `fe524c8a29719da614a6d805409cf72f4743d629993c44dc8a041225edae6411`
        
    *   `f6f49e45a88fb6f33d8f223646028537e13356808d71e09b83047380861c1b44`
        
    *   `4a0e00a6207659ff473f0ad12c0bde760988915a0402c8af4ead60ace90a3eba`
        
    *   `14a66f7b72b4e96774e6d3e79d277040f92c038cc0b867a0d2833563031c0f41`
        
    *   `9d1a08a81cbc2d2754ae81063e575b31d6de276ad9c8a834bd1d745d603225e4`
        
    *   `5b98e273e5ca20850b9ee1db129ff43c970b77f0df4a9362add3505b7ef9b135`
        
    *   `c95235a9e2dc46b79977bcd620d050b427c09efa98f43ce6b3f61fdc88db875f`
        
    *   `bef9366893d8009c4601e566b43975b272e918e56f5b1cc3b45338dc666cfd0f`
        
    *   `4069021a839729a6139094c32254cc040e68068f68f514566d483226ef765ca7`
        
    *   `e99c7a66643851b3cf131cfab5254bdbaf95d6efebc922126ce5537da2ce5c37`
        
    *   `b78e1f2ef5f8e1a2e8b26c506640da440ce58d5679eacadb445d4051f098f8d1`
        
    *   `f3e8198dfc372a83989ddb81b3f569a245e7f84f0aa38e565225e13c7d241c06`
        
    *   `21999de6b1ceabbb350f900d56ea048483839c9a7275b333ae5f542a0d47eee0`
        
    *   `a3b87b497570816f6e9d7136c06b382957c3d9178991726a2bddab0a0c570a0e`
        
    *   `ec5de7c53e11cc2362c813730dd72907d0bfd868fdbc92a7767ec0067249ed39`
        
    *   `7594caf673106dece42b3fae2477955f5fca3545ab5f7e50a2e56198d5afa71a`
        
    *   `40e1e8878f1ea5709e8a312d2e1e2910f76f0f88f249aef8e848fa316c416fd2`
        
    *   `33a33c2de525e57982fe51c0672ef1f96c46aad36706dde24f755f7241d55a4e`
        
    *   `561902f742ee141603ff75644854e6c62906bb318140d0db0609dec4c84e82d4`
        
    *   `3f033394fe1617b66ba98256fc8b0b2da8ae6f0d7142a869eb4465524974112c`
        
    *   `5546839434f121830ad859f4ebb5fea00d4dcaaa7dacc218688e1b8c5b44db72`
        
    *   `2add6937baec9f91fe416e1dfd1d1890d105af389e47d99e45fe53c8a2abfdb2`
        
    *   `ac7bdb1c072cff6a5fef340bacce7745111066e7dbb92f56f48b1d9068467e50`
        
    *   `b39a90afb6ad17aae9d4c8c0bb00f94c4c22cc8fd0355604215fcea6d4a15be2`
        
    *   `cff52b2952c25fac89ccac6397762931e5ae56a0cb6a28a71ac6b26c9cb08654`
        
    *   `04b129b97f7ce8d57daaeb7e8a1149bf37cb15caee022b3da460085ea4e83de1`
        
    *   `b9955c7213ec794e902b80eca39a87e4ed467cf92a19e75a9a5246f9f57749c5`
        
    *   `21b81aeaadea0878fa81a43d21a1f8efad32025454090d4537011e57f3ee43d5`
        
    *   `42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9`
        
    *   `ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f`
        
    *   `cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0`
        
    *   `170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c`
        
    *   `acd2dfee8657712108b761d8dfee9cf486bace454fa63705c4171d6663bae32a`
        
    *   `a7247d1157756582f8b7a31980153c1a2de58165a3933b69b4315ee8ced6793e`
        
    *   `24868f43c6083daa1a418c936158e1a94c28ec6bce5c5a6c95c9311f7017e64d`
        
    *   `8f7d67c51cf8388b6e01526984952fb58bad47dd511d02bf7f73cd4846f84274`
        
    *   `a2e3b6f656b3508bb61587b492f5812020d3c8137c21630de717cb1e3e192592`
        
    *   `9d0e247292544329293d493036b6b93efe2821a1dd9473ad10a9cf6144f747c8`
        
    *   `9c8f36dbca330b6a5e04b5276e223e06efb556d0ffe4532eaa4089d7ac829590`
        
    *   `9588ac123062d96325fa4dbfc845ccb4a20f43e2ddad65584683a81db4cde81b`
        
    *   `939121dd927b1d26065c44ffe89b05614d493b67e92b303d8a799e56a9ef48af`
        
    *   `3b90f4a533418bff83e70ea9bbce1e53864eb897a51e0ca27dfaf2d606e178c9`
        
    *   `f89190d275ac91ec70b16716caa122fe0b11cc7d0b7d32f50cd124ee83bded8a`
        
    *   `86c8e5d3ddf5a10eb5a892afe472eabeebd7f889f72cebbcc232ac1ae79ea19b`
        
    *   `106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42`
        
    *   `9f7b1bc932e9bfab85aa48dbe1f95d2df4681eddbb73ee6b99918b6ee3faacb2`
        
    *   `276fbc0252cca76b505c9f016e081f2afdbffd7407cdcc040a341d9cf5d57e85`
        
    *   `8cf61b6744d9b0caac56099ef089e6fbbae4f75c9971ac97391269a391e525aa`
        
    *   `64589493ec1d77ea9af0da98440d7feda39d27297aa5dc1b3b8a7e5f1bdfcc42`
        
    *   `6de74e183e54bcfc532e2451c88a3159a0ab59622a39cd09de4ff426d139720e`
        
    *   `f483b7572ceff83e02b809f41f04814706177514c5f46bc439589e43eca5c4fa`
        
    *   `31a863efc56c9e6cfddd8db95994930afb8754b171d8b573f4854a0040ea8fe0`
        
    *   `f33af4c168044688b044c34d88a68952a5a168e8b12f805e63be7cd0ff9f72ca`
        
    *   `684a0e5640aa836facc0bbf747d7fc96a4c6ce7b9501ef1e8840a7476b12c37e`
        
    *   `0c2d3d8c8b743dcadaa9260457333440c6adf6532ca5a78b80cc51222ee54a62`
        
    *   `a9ce64317da8c36a1f3465b175de9ebb6e49ec71e59698a70dd3305de89977b9`
        
    *   `3a5b094cd7cf9576d4603da69df8908230653b79092b65269b95264d8a93dffc`
        

## Expert Comments

According to the assessment of the SOC analysis team, KREMLIN (REF9334) represents an important shift for new generation financial malware groups: Shifting the focus from cracking encryption algorithms to exploiting weaknesses in the browser's Operational Flow.

1.  Degradation of Static Disk Protections: Google's introduction of App-Bound Encryption to block malware from reading DPAPI files on hard disks is a big step forward, but KREMLIN has demonstrated that if malware runs with user privileges and exploits the Debugging mechanism (--remote-debugging-port), the disk security mechanism is almost completely disabled while the browser is active.
    
2.  HMAC spoofing poses a challenge for integrity checking: The attacker's successful reverse engineering of Secure Preferences' HMAC calculation algorithm shows that browsers cannot rely solely on local configuration files to protect themselves. There needs to be a digital signature authentication mechanism from a central server (Cloud Integrity Verification) or hard control via Group Policy.
    
3.  Risk of Session Hijacking bypass MFA in Vietnam: Many business organizations and banks in Vietnam have now deployed OTP/FIDO2 for the initial login step. However, after a successful login, the session is completely dependent on the Session Cookie. KREMLIN attacks this blind spot, making it impossible for conventional MFA systems to detect unusual transactions due to the session originating from a valid cookie.
    

## Defense Recommendations

To prevent and eliminate the risk from KREMLIN as well as similar malware strains that exploit browser extensions, the cybersecurity team needs to implement measures according to the following roadmap:

### Urgent Action (0 - 24 hours)

1.  Scan for anomalous browser processes: Implement a query on EDR to immediately detect background chrome.exe or msedge.exe processes that contain the --no-startup-window or --remote-debugging-port parameter.
    
2.  Revoke active Session: If the device is detected with suspicious signs of infection, take action to Revoke/Kill all active Sessions on all Web Email, ERP, Cloud Portal and e-banking systems from the server side.
    

### Short-Term Measures (1 - 7 days)

1.  Control Extension installation via GPO/Registry: Apply centralized administration policy (Group Policy) to completely prevent external users or processes from installing Extensions themselves:
    
    *   Configure policy ExtensionInstallBlocklist = \* (Block all).
        
    *   Configure policy ExtensionInstallAllowlist = List of Extension IDs approved by the business.
        
2.  Additional monitoring rules on SIEM/EDR:
    
    *   Warn when a non-browser process writes/modifies the Secure Preferences file.
        
    *   Monitor JSON-RPC outbound network connections to Ethereum Public Node services (Infura, Alchemy, QuickNode) originating from common workstations.
        

### Long-Term Measures

1.  Deploy Browser Isolation (RBI) architecture: Put employees' Internet access and financial transactions tasks into an isolated browser environment on Cloud/Gateway to completely eliminate the possibility of malicious code interfering with local configuration files.
    
2.  Apply Continuous Session Authentication: Configure internal Web applications and payment gateways to periodically check the validity of Device Binding (which binds the Session Cookie to the device's TPM hardware key), preventing the transfer of Cookies to another machine for use.
    

## References

[KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)

[Malware bypasses browser checks to force install Chrome, Edge extensions](https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/?utm_source=chatgpt.com)

[The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions](https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware?utm_source=chatgpt.com)
