התחברות ל-baba News

חשבון אחד לאתר, לאייפון ולאנדרואיד — המנוי נשאר איתכם.

או קוד במייל

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

Search stories

הקלידו לפחות שני תווים. התוצאות מגיעות מכל המערכות ש-baba קורא.

to move · to open · esc to close

מסוף חי

התחברות ל-baba News

Sign in to keep asking. News Plus removes the daily limit.

או קוד במייל

לראות את התמונה המלאה

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

ביטחון15:49 · Sep 16

Sophisticated KREMLIN Malware Targets Bank Customers, Steals Sensitive Data

מאת קובי ברקת
תורגם ותומצת מתוך Behadrei Haredim על ידי baba
The story · English

Researchers at Elastic Security Labs have uncovered a sophisticated malware campaign, dubbed KREMLIN, that primarily targets bank customers and hijacks Chrome and Edge browsers to steal sensitive information. Active since at least May 2025, the malware's name is misleading, as current evidence points to its origins in Brazil rather than Russia. The infection process typically begins with a JavaScript file disguised as a banking, invoice, or business document. Once the user opens this file, a chain of actions leads to the installation of a malicious browser extension named AVSync System Inc. This extension, appearing legitimate, grants attackers extensive access to browser activities, including the ability to steal cookies, login credentials, browsing history, and data stored within websites.

Furthermore, the extension can capture screenshots, read open page content, and monitor user activity. In some cases, this allows attackers to steal active login tokens, enabling account takeover without needing the password. A particularly unusual aspect of KREMLIN is its installation method. It modifies internal Chrome and Edge profile files, manipulating the browser's authentication mechanisms to make the extension appear user-approved, even when installed without consent. The malware's communication with attackers is also unconventional, utilizing smart contracts on the Ethereum network to obtain new command-and-control server addresses and download additional components, making it difficult for security firms to completely disable its infrastructure.

Elastic's investigation identified 1,515 infected computers, with 98.75% located in Brazil, reinforcing the assessment that the campaign is focused on Brazilian bank customers. There is currently no indication that users in Israel are targeted. Elastic's intervention has disrupted some of the malware's operations, causing infected machines that now check the compromised web address to cease further infection. However, this does not remove the malware from already infected computers. Users are advised to be vigilant about unrecognized browser extensions, especially those requesting broad permissions, and to remove any suspicious ones like AVSync System Inc. immediately, followed by a full security scan. Caution is also urged with email or message attachments disguised as financial documents, as opening the initial file is the trigger for the infection chain.

Read the original at Behadrei Haredim
פתיחת המסוף החי