Crypto news report · source clearly identified

KREMLIN malware leverages Ethereum smart contracts to update attack infrastructure

KREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil.

Security researchers have identified a large‑scale campaign that uses Ethereum smart contracts to dynamically update command‑and‑control (C2) servers for the KREMLIN malware family. The operation, primarily targeting Brazilian banking customers, also installs unauthorized Chrome and Edge extensions to harvest credentials and session data.

Ethereum contracts as a dead‑drop resolver

Since May 2026, KREMLIN operators have deployed three Ethereum contracts that store configuration values pointing infected machines to installer files and malicious browser extensions. By updating on‑chain values, the attackers can change infrastructure references without modifying the malware payload. The most recent contract observed is 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b, with earlier contracts 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 and 0x64Def0A6099c4DE9C413B108EAae85A3C7457615.

Unauthorized browser extensions for credential theft

KREMLIN modifies Chromium’s Secure Preferences files, regenerating the required HMACs and integrity hashes so that malicious extensions load without user approval. The extensions, masquerading as a program called “AVSync,” request access to tabs, cookies, storage and web requests, allowing the theft of saved login information, session tokens and other sensitive data.

Scale of infection and geographic focus

Elastic tracked 1,515 infected systems contacting a registered canary domain, with 98.75% of them geolocated in Brazil. The campaign distributes JavaScript files disguised as bank receipts, invoices or corporate documents, impersonating major Brazilian financial institutions such as Banco do Brasil, Caixa, Bradesco and Santander.

On‑chain financial activity

Analysis of a single Ethereum wallet used to deploy the contracts revealed 82 USDT transfers between June 2025 and August 2026, moving roughly 20,779 USDT in and 19,017 USDT out. Transaction timing aligns with São Paulo business hours, suggesting a Brazil‑based operator.

Defensive insights

Elastic’s registration of an unused domain exploited by the malware’s anti‑analysis check temporarily halted further infection stages, providing a window for defenders to detect and remediate compromised endpoints. Indicators of compromise (IOCs) and MITRE ATT&CK mappings have been published for endpoint, browser and network monitoring.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 16, 2026, 12:26 PM
Original headline
KREMLIN malware uses Ethereum to update attack servers
View original report ↗