
KREMLIN malware silently installs AVSync extension in Chrome and Edge to steal passwords
- —KREMLIN disguises itself as invoices, receipts and bank documents in JavaScript format
- —The AVSync extension is installed without a permission prompt by editing Chromium profile files
- —AVSync harvests passwords, cookies, sessions, screenshots and browsing history
- —The threat has been active since mid-2025 and is tied to bank impersonation campaigns
Why it matters: A compromised browser exposes crypto wallets and exchange accounts, so users should audit extensions and reset passwords from a clean device.
Source: DiarioBitcoin