“Chrome malware” — 45 distilled results

Brazilian banking malware KREMLIN steals credentials via browser extensions

Security researchers documented a Brazilian banking malware operation called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions to steal credentials and session tokens. By September 16, 2026, the malware was using Ethereum smart contracts for command-and-control infrastructure resistant to takedown efforts.

Multiple critical cybersecurity vulnerabilities disclosed

Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.

Chaos gang deploys msaRAT backdoor via browser routing

The Chaos ransomware gang is using msaRAT, a Rust-based backdoor, to hide command-and-control communication by routing it through Chrome or Edge browsers to evade detection. Cisco Talos found the malware on a compromised Windows machine before the gang deployed ransomware encryption.

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the TAG-195, also called Golden Chickens or Venom Spider, malware-as-a-service ecosystem, which supplies tooling to financially motivated criminal operators.

⚪️ KREMLIN Banker Steals Credentials and Session Tokens from Chrome and Edge 🗨️ Researchers at Elastic Security Labs have analyzed the KREMLIN banking malware, which can install malicious extensions

⚪️ KREMLIN Banker Steals Credentials and Session Tokens from Chrome and Edge 🗨️ Researchers at Elastic Security Labs have analyzed the KREMLIN banking malware, which can install malicious extensions for Chrome and Edge on an infected machine without the user’s knowledge.

🤖 PEEP: a Chromium post-compromise toolkit that injects a malicious "bookmarks" extension directly into Chrome/Edge profiles, forging Secure Preferences to bypass Web Store checks and user prompts. E

🤖 PEEP: a Chromium post-compromise toolkit that injects a malicious "bookmarks" extension directly into Chrome/Edge profiles, forging Secure Preferences to bypass Web Store checks and user prompts. Enables persistent host command execution after admin access.

Tech firms warn of rising AI-enabled cyberattack threats globally

On 27–28 August 2026, OpenAI led an open letter signed by nearly 130 organizations—including Anthropic, Microsoft, Google, Amazon, and Cisco—warning of escalating AI-enabled cyberattacks and urging coordinated global cyber defenses. The coalition cautioned that sophisticated AI-powered attacks could proliferate within months without coordinated action.

Multiple unrelated cybersecurity incidents reported

Between August 19–20, 2026, multiple data breaches were announced on cybercrime forums: CONALEP Morelos (Mexico, 24K+ student records), Hamara (Zimbabwe, 11K+ agricultural users), Quero Namoro (Brazil, 19K users, 5GB backup), Adornis GmbH (source code), and University of Delhi (database advertised for sale). No single coordinated story; these are separate incidents.