Malware Is Bypassing Browser Checks to Force-Install Extensions. Here's How
Emily Davis ·
Listen to this article~4 min
A banking malware toolkit called KREMLIN is bypassing browser checks to force-install malicious Chrome and Edge extensions. If you use antidetect browsers, here's what you need to know.
You know that little voice that says "it's just a browser extension, how bad could it be?" Yeah, that voice is about to get a reality check. Since mid-2025, a banking malware crew has been quietly using a toolkit called KREMLIN to sneak malicious extensions into Chrome and Edge. Not by asking nicely. By bypassing the browser checks that are supposed to keep this stuff out.
If you work with antidetect browsers or manage multiple profiles, this one's worth your attention. Here's what's actually going on.
### What KREMLIN Actually Does
KREMLIN doesn't rely on you downloading something sketchy from a random site. It slips past the safeguards browsers use to verify extensions. Once inside, the extension sits there like it belongs. Then it starts harvesting:
- Saved credentials
- Session tokens
- Cookies and authentication data
- Anything else it can grab
That's a problem for anyone, but it's a particular headache if you're juggling dozens of browser profiles. One compromised session can ripple across everything linked to it.
### Why Antidetect Browser Users Should Care
Antidetect browsers are built to keep profiles isolated. That's the whole point. But isolation doesn't help if malware gets a foothold at the browser level. KREMLIN doesn't care how many profiles you've set up. It just wants in.
Here's the thing: most people assume antidetect tools are bulletproof. They're not. They're private, sure. But private isn't the same as immune. A forced extension install can still read what's happening inside a session, even if that session looks like a totally different machine to the outside world.
> "The best antidetect browser in the world won't save you if you're not paying attention to what's running inside it."
That's not fearmongering. That's just how it works.
### What You Can Actually Do About It
You don't need to panic. You need to pay attention. A few practical moves:
- Audit your extensions. If you don't recognize it, remove it.
- Keep your browser updated. Vendors patch these bypasses, but only if you let them.
- Use separate profiles for sensitive work. Don't mix banking with browsing.
- Check permissions. An extension that wants to read all your data on all sites should earn that trust.
And if you're running an antidetect setup, treat each profile like its own little kingdom. Don't let one get compromised and take the rest down with it.
### The Bigger Picture
KREMLIN is a reminder that browser security is a moving target. The bad guys aren't just phishing anymore. They're finding ways around the walls we thought were solid. That doesn't mean antidetect browsers are useless. Far from it. It means they're one layer, not the whole castle.
Stay sharp. Check your extensions. And don't assume "private" means "safe." Those are two very different things.