KREMLIN malware uses Ethereum to update attack servers

1 day ago 3



Security researchers have traced more than 1,500 KREMLIN malware infections after uncovering a Brazilian banking campaign that uses Ethereum smart contracts to update attack infrastructure and malicious browser extensions to steal credentials and session data. Summary Elastic tracked KREMLIN across seven campaigns using malicious browser extensions against Brazilian banking users primarily. Ethereum smart contracts let KREMLIN operators update command servers and payload locations without changing malware. Elastic observed 1,515 infected systems contacting its registered canary domain, with 98.75% located in Brazil. KREMLIN manipulates Chromium Secure Preferences to install malicious Chrome and Edge extensions without user approval. Researchers traced 82 USDT transfers through the wallet used to deploy and update malicious contracts. Elastic Security Labs disclosed the operation in a Sept. 14 technical report after tracking the activity under REF9334 since May 2025. Researchers followed seven campaigns over roughly 15 months and linked the latest versions to Chrome and Microsoft Edge extensions capable of collecting browser credentials, cookies, session tokens and other sensitive i...

Read Entire Article