AVSync is a malicious Chromium browser extension deployed by the Brazil-focused KREMLIN banking-malware operation. KREMLIN installs it without user interaction into Google Chrome and Microsoft Edge profiles by bypassing Chromium extension-integrity controls using the Phantom Extension technique. AVSync impersonates a legitimate extension and obtains access to browser tabs, cookies, storage, and network requests. It captures screenshots, enumerates open tabs and browsing data, collects cookies, stored web data, passwords, and user-entered form text, enabling credential theft and reuse of authenticated sessions. It can also intercept HTTP requests, inject attacker-controlled content into web pages, and redirect user clicks, providing attackers with browser-level control over banking and other online sessions. KREMLIN campaigns primarily target Brazilian users through Portuguese-language financial-document lures impersonating banks and payment services; the associated installer and supporting malware operate on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The KREMLIN-deployed malicious extension is named AVSync (extension ID ndpbidppejfanjbhfgjlohfanbfbklff) and uses WebSocket communication via /google_ws/ and HTTP polling through /google_api/*.css.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
расширение ... перехватывает пароли и любой текст, который пользователь вводит в формы. | расширение способно перехватывать HTTP-запросы, внедрять HTML на страницы, перенаправлять клики.
После установки вредоносное расширение похищает файлы cookie, содержимое localStorage и sessionStorage... Сам KREMLIN тоже ... может похищать ... файлы cookie.
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
расширение ... перехватывает пароли и любой текст, который пользователь вводит в формы. | расширение способно перехватывать HTTP-запросы, внедрять HTML на страницы, перенаправлять клики.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chrome and Edge extension deployed by KREMLIN through a Chromium integrity-check bypass. It steals cookies, localStorage and sessionStorage contents, passwords, form input, screenshots, HTML, tab information, and browser history; it can also intercept HTTP requests, inject HTML, redirect clicks, and receive commands over WebSocket.
A malicious browser extension deployed by KREMLIN that masquerades as AVSync. It abuses extensive browser permissions to collect credentials, cookies, stored browser data, screenshots, open-tab information, and typed text, and can inject attacker-controlled page content.
The malicious browser extension installed by KREMLIN. It masquerades as AVSync and abuses broad Chrome/Edge permissions to collect cookies, stored browser data, typed text, screenshots, and tab information, while also enabling web-page injection and data exfiltration.
Malicious Chromium extension deployed by KREMLIN. It captures screenshots, steals cookies and browser storage, logs keystrokes, injects HTML, intercepts HTTP requests, and redirects traffic. Its C2 infrastructure can be resolved dynamically via Ethereum smart contracts or an ENDPOINT_DINAMIC endpoint.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.