
Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies
According to the indictment, the 43-year-old CISO allegedly spent years infiltrating companies and private computers, using malware to steal sensitive information, access passwords and remotely activate cameras and microphones.
Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The group itself has no connection to the charges.
According to the indictment, Bar infiltrated malware into the computer systems of 26 companies, two kibbutzim and private individuals, allowing him to execute thousands of remote commands and collect passwords, correspondence, sensitive business information and recordings from cameras and microphones.
The indictment alleges that after Bar learned that his cyberattacks had been discovered, he used artificial intelligence tools to develop more sophisticated malware and continued extracting sensitive business and personal information.
The indictment alleges that Bar systematically created, distributed and operated malicious software from 2019 until his arrest last month, using it as an offensive cyber tool. According to the prosecution, he developed some of the malware with the help of AI tools, including Claude.
The list of companies allegedly targeted by Bar, included in an appendix to the indictment, includes Sheldor, Gindi and Machpel Mishmarot. The two kibbutzim named in the indictment are Gazit and Kfar Menachem.
The case took a particularly striking turn on April 30. According to the indictment, Bar was contacted by investigators from the National Cyber Directorate, which was examining a large-scale attack on companies in the Israeli economy and suspected that the Hamat Group had also been compromised.
Because of his position as the company’s CISO, Bar was given details of the incident and a tool designed to locate the malware in Hamat’s computer systems.
But according to the indictment, the person who received the tool and was expected to help investigators find the attacker was himself the alleged attacker.
Bar allegedly concealed his involvement, continued speaking with the cyber investigators for about two weeks and did not stop his activities. On the contrary, the prosecution alleges that after learning that his malware had been detected, he developed a new and more sophisticated program and used it to infiltrate the systems of additional companies.
The indictment contains 11 counts and attributes to Bar, among other offenses, 28 counts of unauthorized access to computer material in order to commit another offense, 44 counts of introducing a computer virus, 155 counts of violating privacy, as well as multiple counts involving theft and prohibited software activity.
According to the State Attorney’s Office, the companies suffered total damages of approximately NIS 1.5 million ($500,000).
The prosecution is seeking to keep Bar in custody until the end of the proceedings, arguing that he poses a danger and could obstruct the investigation or judicial process. A court ruled today that he will remain in custody at this stage, pending a further decision.
According to the indictment, Bar’s operation initially relied in part on everyday tools. As early as June 2019, he maintained a Telegram account under the username “MIKOSS” and created 19 bots that he used to control the malicious software installed on computers and networks belonging to various users.
The malware could take screenshots, activate cameras and microphones to record video and audio, extract usernames and passwords stored on computers, retrieve credit card information, generate lists of saved files, download files and remotely shut down computers.
This year, according to the indictment, Bar created two more sophisticated malware programs designed to collect and retrieve information from compromised computers. Their capabilities allegedly included extracting identification details, passwords and access permissions stored on computers or in browsers; recording keystrokes in real time to capture passwords, messages and other sensitive information; viewing and recording screens in real time; and recording sound through microphones.
In organizational environments, the malware could allegedly spread between computers and systems, alter operating systems, take control of computers, search for cryptocurrency wallets and disable security systems.
Between February and August of this year, according to the indictment, Bar sent thousands of commands to the computers of the companies he allegedly attacked. Hundreds of those commands were used for reconnaissance and mapping of organizational systems, while others were used to move between computers on networks, take screenshots, activate cameras, download files and extract passwords and identification information.
The affair was discovered on April 27, when one of the affected companies suspected that malware had been installed on its computers and hired a company specializing in cyber incident response and defense.
An examination of the findings raised concerns that the attack was not an isolated incident. According to the indictment, investigators feared “widespread harm to the Israeli economy.”
From June until his arrest by the Lahav 433 cyber unit in August, he allegedly sent more than 1,200 different commands to compromised computers using the new malware.
The alleged intrusion went far beyond the theft of corporate information.
According to the indictment, Bar accessed cameras and microphones located inside homes, bedrooms and even a hotel room, recording people without their knowledge.
In one case, he allegedly activated the computer camera of a product manager and recorded her sleeping in her bedroom. In another, he allegedly activated the computer camera of a vice president of business development while she was in a hotel room. On the same day, according to the indictment, he also copied a file containing her passwords, including login information for her HMO account.
Another screenshot allegedly captured a Zoom call during which significant company projects and transactions were discussed.
In another case, Bar is accused of infiltrating a computer used by a sales representative and her three minor daughters. According to the indictment, he repeatedly activated the computer’s camera and recorded the girls in the living room and bedroom, including when they were partially clothed and in intimate situations. He also allegedly activated the microphone and recorded conversations among people in the home.
The prosecution alleges that the recordings and other material remained in Bar’s possession until his arrest.
Other computers, according to the indictment, contained private correspondence with family doctors, searches about medical issues, WhatsApp conversations, email accounts, Netflix and credit company login details, and personal information about customers.
In one case, investigators allegedly found a screenshot showing a company’s banking platform, through which its accounts in Italy could be accessed, along with what appeared to be a potential bank transfer to an Italian law firm.
In its request to keep Bar in custody, the prosecution said investigators found malware, links to control servers and thousands of files transferred from compromised computers on his devices.
Some of the files were allegedly organized into folders on Bar’s personal computer according to the names of victims. They included passwords, identification information, screenshots and videos recorded through computer cameras.
Investigators also found what the prosecution described as Bar’s activity history involving the artificial intelligence software Claude, which he allegedly used to develop the malware.
The prosecution also obtained messages from 12 women, including mothers of minor daughters and a minor who was herself allegedly affected, describing their shock after learning about the alleged activity. Representatives of the targeted companies also described the damage they said they had suffered, including financial losses that reached hundreds of thousands of shekels at some companies.
According to the detention request, Bar initially told investigators that he had carried out the actions with the authorization and permission of his employers. He later, according to the prosecution, admitted to a significant portion of the alleged offenses, including creating two malicious programs using an AI system and described their capabilities and the companies into which they were allegedly infiltrated.
He denied any connection to the malware controlled through his Telegram account. According to the prosecution, Bar claimed that an unknown person had taken over the account, used it to infiltrate other people’s computers and installed the malware on them.
The State Attorney’s Office is seeking to keep Bar in custody until the end of the proceedings, arguing that he poses a danger to the public and presents a risk of obstructing the proceedings. Prosecutors argue that his technological capabilities, his ability to remotely activate malware and the possibility that some of the malware may still be present on compromised computers make house arrest or electronic monitoring insufficient.














