KREMLIN Malware Uses Ethereum Smart Contracts for Update and Expansion
KREMLIN malware has been linked to over 1,500 infections in Brazil after researchers discovered that it uses Ethereum smart contracts to update attack infrastructure and malicious browser extensions. The campaign, dubbed REF9334, was tracked by Elastic across seven campaigns using malicious browser extensions against Brazilian banking users primarily.
The use of Ethereum smart contracts allows KREMLIN operators to update command servers and payload locations without changing the malware itself. Researchers observed 1,515 infected systems contacting the registered canary domain, with 98.75% located in Brazil.
KREMLIN manipulates Chromium Secure Preferences to install malicious Chrome and Edge extensions without user approval. The attackers used the blockchain as a dead-drop resolver: infected machines read configuration values from the contracts to locate external infrastructure controlled or abused by the operators.