KREMLIN Malware Exploits Ethereum Smart Contracts to Attack Infrastructure

By: x.com|2026/09/16 10:13:02

SlowMist has issued a security alert regarding the KREMLIN malware ecosystem associated with the Brazilian banking malware operation REF9334, which has been active since at least May 2025. This malware uses a multi-stage loader and malicious browser extensions to steal user credentials, session tokens, and sensitive data, capable of bypassing Chromium integrity mechanisms such as Secure Preferences, HMAC, and App-Bound encrypted hashes without the user's knowledge, forcibly installing malicious extensions in Chrome and Edge browsers. The operation utilizes Ethereum smart contracts as a "dead-drop resolver" to dynamically update C2 endpoints and payload hosting addresses, enhancing the resilience of its infrastructure against attacks. After researchers registered a network kill switch, they observed 1,515 infected hosts connecting back, with 98.75% located in Brazil.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]