Researchers describe a banking-focused malware campaign running since mid-2025 that uses a toolkit called KREMLIN to sneak malicious add-ons into Chrome and Edge, sidestepping the browsers' normal installation safeguards. Once in place, the extensions harvest login credentials, active session tokens, and other private information from victims.
Read the full story at Bleeping Computer