PANews|Sep 16, 2026 10:57
[SlowMist: KREMLIN Malware Utilizes Ethereum Smart Contracts for Dynamic Updates to Attack Infrastructure]
According to monitoring by SlowMist, a Brazilian banking malware operation, REF9334, which has been active since at least May 2025, was recently disclosed. Its KREMLIN malware ecosystem employs multi-stage loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data. The malicious extensions can bypass Chromium integrity mechanisms, including Secure Preferences, HMAC, and App-Bound encrypted hashes, to install themselves into Chrome and Edge without user approval. The operation also uses Ethereum smart contracts as a 'dead letter resolver' to dynamically update C2 endpoints and payload hosting locations. After registering a Canary domain on the network, analysts observed 1,515 infected hosts checking in, 98.75% of which were located in Brazil.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink