Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
KREMLIN malware uses Ethereum smart contracts to update attack servers and steal banking credentials
00

KREMLIN malware uses Ethereum smart contracts to update attack servers and steal banking credentials

Sep 16, 2026

Security researchers at Elastic Security Labs have exposed KREMLIN, a Brazilian banking malware campaign active since May 2025. The operation bypasses Chromium browser security to install malicious extensions on Chrome and Edge, stealing credentials and session tokens. Notably, KREMLIN uses Ethereum smart contracts as dead-drop resolvers to dynamically update its command servers. Researchers intercepted the campaign's anti-analysis check, identifying 1,515 infected hosts, 98.75% of which are in Brazil.

KREMLIN malware operation

  • ▪The KREMLIN attack chain begins with a JavaScript file disguised as a bank receipt, invoice, or corporate document that must be manually executed by the victim.
  • ▪The KREMLIN installer abuses a legitimate SentinelOne binary named SentinelMemoryScanner.exe to sideload its unsigned main payload, which impersonates SentinelAgentCore.dll.
  • ▪Elastic Security Labs published a technical report on September 14, 2026, detailing a Brazilian banking malware operation tracked as REF9334 that delivers a toolkit called KREMLIN.
  • ▪The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data.

Ethereum smart contracts as infrastructure

  • ▪The KREMLIN malware uses Ethereum smart contracts as dead-drop resolvers, allowing operators to change infrastructure references on-chain while leaving the initial malware unchanged.
  • ▪The KREMLIN malware operation transitioned to using Ethereum smart contracts on May 19, 2026, to store configuration values and dynamically update command-and-control endpoints.
  • ▪Elastic Security Labs identified three Ethereum smart contracts linked to KREMLIN, including the active contract 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b and earlier contracts 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 and 0x64Def0A6099c4DE9C413B108EAae85A3C7457615.

Chromium browser extension hijacking

  • ▪The KREMLIN installer utilizes a publicly documented integrity bypass technique known as Phantom Extension or GhostChrome-X to register its malicious extension by modifying the protection.macs JSON object.
  • ▪The malicious KREMLIN browser extension masquerades as software named AVSync System Inc. and requests extensive access to browser tabs, cookies, storage, and the webRequest API.
  • ▪KREMLIN bypasses Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs and App-Bound encrypted hashes to install malicious extensions on Google Chrome and Microsoft Edge without user approval.

Brazilian banking credential theft

  • ▪The KREMLIN extension periodically polls a /google_api/ endpoint via requests masquerading as CSS file fetches to upload stolen browser data and fetch targeting configurations.
  • ▪The KREMLIN browser extension establishes a WebSocket channel with its command-and-control server to execute commands such as taking screenshots, stealing cookies, and extracting full HTML source code.
  • ▪The KREMLIN campaign distributes lures that impersonate a dozen Brazilian financial brands, including Banco do Brasil, Caixa, Bradesco, Sicoob, C6 Bank, Inter, BTG, Safra, PagBank, PicPay, Santander, and Mercado Pago.

Campaign infection scope

  • ▪Elastic Security Labs counted 1,515 infected systems contacting its registered canary domain, with 98.75% of those systems geolocated in Brazil.
  • ▪Elastic Security Labs registered an unused network canary domain used by KREMLIN for anti-analysis checks, which temporarily degraded the campaign's defense mechanisms and halted the infection chain on contacting systems.

Attribution analysis

  • ▪Despite the name KREMLIN, Elastic Security Labs found no evidence connecting the malware campaign to Russia, noting that the toolkit name comes from the malware author's handle.
  • ▪Elastic Security Labs identified a single Ethereum wallet used to deploy and update KREMLIN's malicious contracts, which was associated with 82 USDT transfers totaling approximately 20,778.97 USDT received and 19,016.96 USDT sent between June 19, 2025, and August 24, 2026.
  • ▪The transaction timing of the KREMLIN-linked Ethereum wallet aligned with working hours in the UTC-3 time zone used by São Paulo, suggesting Brazil as a plausible operator location.

2 sources

Thehackernews
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
View source article
Crypto
KREMLIN malware uses Ethereum to update attack servers
View source article

Story comments

Loading comments…

Related entities

Brazil

Related Projects

Ethereum

Topics

EthereumSmart contractsCrypto security