KREMLIN extension exfiltrating cookies/session data via /google_api/108766d0.css
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
Microsoft Sentinel (KQL)

