Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Security15:49 · Sep 16

Sophisticated KREMLIN Malware Targets Bank Customers, Steals Sensitive Data

By קובי ברקת
Translated & summarized from Behadrei Haredim by baba
The story · English

Researchers at Elastic Security Labs have uncovered a sophisticated malware campaign, dubbed KREMLIN, that primarily targets bank customers and hijacks Chrome and Edge browsers to steal sensitive information. Active since at least May 2025, the malware's name is misleading, as current evidence points to its origins in Brazil rather than Russia. The infection process typically begins with a JavaScript file disguised as a banking, invoice, or business document. Once the user opens this file, a chain of actions leads to the installation of a malicious browser extension named AVSync System Inc. This extension, appearing legitimate, grants attackers extensive access to browser activities, including the ability to steal cookies, login credentials, browsing history, and data stored within websites.

Furthermore, the extension can capture screenshots, read open page content, and monitor user activity. In some cases, this allows attackers to steal active login tokens, enabling account takeover without needing the password. A particularly unusual aspect of KREMLIN is its installation method. It modifies internal Chrome and Edge profile files, manipulating the browser's authentication mechanisms to make the extension appear user-approved, even when installed without consent. The malware's communication with attackers is also unconventional, utilizing smart contracts on the Ethereum network to obtain new command-and-control server addresses and download additional components, making it difficult for security firms to completely disable its infrastructure.

Elastic's investigation identified 1,515 infected computers, with 98.75% located in Brazil, reinforcing the assessment that the campaign is focused on Brazilian bank customers. There is currently no indication that users in Israel are targeted. Elastic's intervention has disrupted some of the malware's operations, causing infected machines that now check the compromised web address to cease further infection. However, this does not remove the malware from already infected computers. Users are advised to be vigilant about unrecognized browser extensions, especially those requesting broad permissions, and to remove any suspicious ones like AVSync System Inc. immediately, followed by a full security scan. Caution is also urged with email or message attachments disguised as financial documents, as opening the initial file is the trigger for the infection chain.

Read the original at Behadrei Haredim
Open the live terminal