Short version:
- Malware got onto Windows PC.
- From the compromised machine, spying on credentials is trivial.
That's it. All the analysis about how they inject some code into some browser and communicate with their server is a smoke screen.
Our most favourite OS is blatantly insecure.