Security researchers at Elastic Security Labs have exposed KREMLIN, a Brazilian banking malware campaign active since May 2025. The operation bypasses Chromium browser security to install malicious extensions on Chrome and Edge, stealing credentials and session tokens. Notably, KREMLIN uses Ethereum smart contracts as dead-drop resolvers to dynamically update its command servers. Researchers intercepted the campaign's anti-analysis check, identifying 1,515 infected hosts, 98.75% of which are in Brazil.
Story comments
Loading comments…