Brazilian Banking Malware 'KREMLIN' Uses Ethereum to Hide Its Command Infrastructure
Security researchers at Elastic Security Labs have traced more than 1,500 infections linked to a malware operation dubbed KREMLIN, which despite its name has no confirmed connection to Russia. The campaign, tracked since May 2025, primarily targets systems in Brazil through Portuguese-language lures impersonating local banks, and deploys malicious Chrome and Microsoft Edge browser extensions designed to steal credentials, cookies and session tokens.
What makes this operation notable is its use of Ethereum smart contracts as a way to store and update configuration data, effectively acting as a 'dead-drop' system that points infected machines toward attacker-controlled infrastructure. This does not exploit any weakness in Ethereum itself; rather, it lets attackers change server locations and hosted files by updating values on the blockchain, without needing to alter the original malware. Elastic identified several contracts used over time, with the most recent one still active when the report was published on September 14. Blockchain security firm SlowMist separately flagged the blockchain component in an alert issued two days later.
Because the malicious infrastructure can shift without warning while blockchain records remain public and hard to take down, this technique makes the campaign more resilient to standard takedown efforts. Businesses using online banking, particularly those with a presence in Brazil or operations connected to Brazilian financial institutions, should be aware that browser extensions remain a key vector for credential theft.