KREMLIN Malware Exploits Ethereum Smart Contracts to Dynamically Update Attack Infrastructure
Odaily reports, according to SlowMist monitoring, a Brazilian banking malware operation tracked as REF9334, active since May 2025, has recently been exposed. Its KREMLIN malware ecosystem uses multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data, and can bypass Chromium integrity mechanisms to install itself into Chrome and Edge browsers without user approval. The operation also uses Ethereum smart contracts as a "dead drop resolver" to dynamically update C2 endpoints and payload hosting locations. After analysts registered a Canary domain, they observed 1,515 infected hosts checking in, 98.75% of which were located in Brazil.
