AVSync is a malicious Chromium browser extension used by the KREMLIN Brazil-focused banking-malware operation. It is installed directly into Google Chrome and Microsoft Edge profiles outside official extension stores, with the broader KREMLIN toolkit modifying Chromium preference-validation protections to make the extension appear authorized. Campaigns use Portuguese-language banking, invoice, receipt, and payment-themed lures targeting Brazilian users and financial-service customers. AVSync requests access to browser tabs, cookies, storage, and network requests. It can enumerate tabs, capture screenshots and typed text, collect cookies and browser-stored data, intercept HTTP requests, inject attacker-controlled web content, and redirect browsing. Theft of authenticated session cookies enables account-session reuse and account takeover. AVSync communicates with operator infrastructure using WebSocket communications and HTTP polling. KREMLIN activity has also employed sandbox evasion, scheduled-task persistence, blockchain-based configuration retrieval, and DLL side-loading in the endpoint infection chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The KREMLIN-deployed malicious extension is named AVSync (extension ID ndpbidppejfanjbhfgjlohfanbfbklff) and uses WebSocket communication via /google_ws/ and HTTP polling through /google_api/*.css.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
“A stolen session cookie can let an intruder reuse an authenticated account.”
“It can take screenshots, list open tabs, collect cookies and stored web data, capture typed text, and inject attacker-controlled content into pages.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious browser extension deployed by KREMLIN that masquerades as AVSync. It abuses extensive browser permissions to collect credentials, cookies, stored browser data, screenshots, open-tab information, and typed text, and can inject attacker-controlled page content.
The malicious browser extension installed by KREMLIN. It masquerades as AVSync and abuses broad Chrome/Edge permissions to collect cookies, stored browser data, typed text, screenshots, and tab information, while also enabling web-page injection and data exfiltration.
Malicious Chromium extension deployed by KREMLIN. It captures screenshots, steals cookies and browser storage, logs keystrokes, injects HTML, intercepts HTTP requests, and redirects traffic. Its C2 infrastructure can be resolved dynamically via Ethereum smart contracts or an ENDPOINT_DINAMIC endpoint.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.