BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

KREMLIN Malware Exploits Ethereum Smart Contracts to Dynamically Update Attack Infrastructure

Odaily reports, according to SlowMist monitoring, a Brazilian banking malware operation tracked as REF9334, active since May 2025, has recently been exposed. Its KREMLIN malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data, and can bypass Chromium integrity mechanisms to install itself into Chrome and Edge browsers without user approval. The operation also uses Ethereum smart contracts as a "dead drop resolver" to dynamically update C2 endpoints and payload hosting locations. After analysts registered a Canary domain, they observed 1,515 infected hosts checking in, 98.75% of which were located in Brazil.