The fake extension that could steal your passwords from Google's browser
Security researchers at Elastic Security Labs have uncovered a sophisticated malware campaign using fake browser extensions to steal passwords and banking details. The malware, 'Kremlin', disguises itself as an antivirus extension and uses the Ethereum blockchain to evade detection. So far, 1,515 infections have been identified, mostly in Brazil.
Security researchers at Elastic Security Labs have uncovered a sophisticated malware campaign exploiting fake browser extensions in Google Chrome and Microsoft Edge. The malware, named 'Kremlin', begins with fake documents such as payment invoices sent to victims. After installation, it installs an extension called 'AVSync System Inc' that poses as an antivirus but actually monitors browsing activity, takes screenshots, and steals cookies and login credentials. To evade detection, the malware uses advanced technology and manages its communication over the Ethereum blockchain. It also checks if it is running in a protected testing environment and refuses to operate if it detects one. So far, 1,515 infections have been identified, with 98% concentrated in Brazil. Researchers managed to halt its spread using simulated servers. The article concludes with recommendations for protection: avoid downloading files from unknown sources and check the extensions installed in your browser.
The fake extension that could steal your passwords from Google's browser