Brazilian Malware Operation Uses Ethereum Smart Contracts
Security researchers have uncovered a sophisticated malware operation known as KREMLIN that uses Ethereum smart contracts to update its attack infrastructure. Elastic Security Labs, the team behind the discovery, tracked over 1,500 infections linked to the campaign, with the majority of affected systems located in Brazil.
The malware's use of Ethereum contracts allows its operators to change command-and-control infrastructure without modifying the initial malware code. This design lets attackers update configuration values on-chain while keeping the underlying malware unchanged. Elastic researchers found that infected machines read configuration values from the contracts to locate external infrastructure controlled or abused by the operators.
The KREMLIN campaign distributes JavaScript files disguised as bank receipts, invoices, or corporate documents to initial infection. Once a victim executes the lure, the loader checks the environment before progressing through later stages. The malware's browser component uses a technique that lets an unauthorized extension appear properly registered inside Chromium-based browsers.
Elastic Security Labs discovered the operation in September 2026 after tracking it under REF9334 since May 2025. Researchers followed seven campaigns over roughly 15 months and linked the latest versions to Chrome and Microsoft Edge extensions capable of collecting browser credentials, cookies, session tokens, and other sensitive information.