Security· ★★★· bearish·

KREMLIN malware silently installs AVSync extension in Chrome and Edge to steal passwords

  • KREMLIN disguises itself as invoices, receipts and bank documents in JavaScript format
  • The AVSync extension is installed without a permission prompt by editing Chromium profile files
  • AVSync harvests passwords, cookies, sessions, screenshots and browsing history
  • The threat has been active since mid-2025 and is tied to bank impersonation campaigns
Why it matters: A compromised browser exposes crypto wallets and exchange accounts, so users should audit extensions and reset passwords from a clean device.
Source: DiarioBitcoin