Search the site
Press ESC to close
LIVE
Loading...
Updating...

KREMLIN Malware Exploits Ethereum Smart Contracts for C2 Infrastructure

Wei Liang Mo
Fact-checked
3 min read
410 words
Share

Security researchers from SlowMist have identified a sophisticated Brazilian banking malware campaign, designated as REF9334, which utilizes the Ethereum blockchain to maintain its malicious infrastructure. Active since at least May 2025, the ecosystem utilizes the KREMLIN malware to target sensitive user data through a series of multi-stage loaders and unauthorized browser extensions. The most notable technical evolution in this campaign is the integration of smart contracts as a decentralized mechanism for updating command-and-control (C2) endpoints.

Technological Bypasses and Browser Exploitation

The KREMLIN malware ecosystem focuses on the theft of credentials, session tokens, and sensitive financial data. According to the investigation, the attackers have developed methods to install malicious extensions in Google Chrome and Microsoft Edge without obtaining user approval. This is achieved by bypassing several critical Chromium integrity mechanisms, including Secure Preferences, HMAC, and App-Bound encrypted hashes, which are designed to prevent unauthorized modifications to browser settings.

The campaign's architecture relies on a complex delivery system:

  • Identification of vulnerable systems through initial infection vectors.
  • Deployment of multi-stage loaders to establish persistence.
  • Execution of scripts to disable browser security protocols.
  • Injection of malicious extensions capable of real-time data exfiltration.

Ethereum Smart Contracts as Dead Letter Resolvers

A significant feature of REF9334 is its use of the Ethereum network as a "dead letter resolver." By utilizing the immutable nature of smart contracts, the threat actors can dynamically update their C2 endpoints and payload hosting locations. This method allows the malware to query the blockchain to retrieve the latest server addresses, making it significantly harder for security providers to take down the infrastructure through traditional domain blacklisting.

The campaign uses Ethereum smart contracts to dynamically update C2 endpoints and payload hosting locations, ensuring the resilience of the attack infrastructure against conventional intervention.

This decentralized approach ensures that even if specific hosting providers take down malicious files, the malware-infected clients can automatically find new source locations by reading updated data directly from the Ethereum blockchain.

The discovery of the KREMLIN malware highlights the growing trend of cybercriminals leveraging Web3 technologies to enhance the stealth and longevity of traditional banking trojans. As of September 16, 2026, security experts recommend that users monitor their browser extension lists for unrecognized entries and ensure that their systems are updated with the latest security patches to defend against Chromium-based vulnerabilities. The integration of blockchain into malware distribution underscores the necessity for cross-industry cooperation between cybersecurity firms and blockchain developers.

Frequently Asked Questions

Quick answers to the most common questions about this topic.