Overview of KREMLIN Malware Operation
Recent analysis by security experts at Elastic Security Labs has unveiled a substantial malware operation known as KREMLIN, which has infected over 1,500 systems, predominantly in Brazil. This scheme, identified as campaign REF9334, primarily focuses on Brazilian banking institutions, leveraging Ethereum smart contracts to facilitate updates to their attack infrastructure. The findings were disclosed in a detailed report released on September 14, 2025, after researchers monitored the operation since May 2025.
Malware Characteristics and Techniques
The KREMLIN malware harnesses multi-stage loaders and harmful browser extensions designed to steal sensitive user information, including credentials, session tokens, and cookies, primarily through extensions for Chrome and Microsoft Edge. An alert was also issued on September 16 by SlowMist, emphasizing the importance of recognizing the operational ties to Ethereum and its embedded contracts that manage the malware’s command-and-control mechanisms.
Despite bearing a name suggestive of Russian origins, Elastic researchers found no substantiation linking this campaign directly to Russia. The title KREMLIN derives from the alias of the malware’s creator, while the operation predominantly employs Portuguese for its impersonation tactics, creating fake personas of reputable Brazilian banks such as Banco do Brasil and Bradesco.
Use of Ethereum in KREMLIN’s Infrastructure
The use of Ethereum in this context became evident after researchers began observing malicious smart contracts connected to KREMLIN starting May 2026. The primary contract, linked to KREMLIN’s infrastructure, was discovered on May 19. Subsequent contracts introduced an advanced structure, facilitating dynamic command changes via a key-value system. Among the contracts scrutinized, 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b was identified as currently active at the time of the report.
Elastic clarified that these contracts do not exploit Ethereum’s blockchain directly; rather, they serve as dead-drop resolvers, where compromised machines pull configuration data to assist with locating the attackers’ infrastructure. This enables the operators to modify their infrastructural details simply by refreshing on-chain data without altering the malware itself. Notably, this design has been exploited multiple times, resembling tactics seen in malware utilizing npm packages and other blockchain networks like BNB Chain for similar purposes.
Malicious Browser Extensions and Infection Mechanism
KREMLIN employs a method to maliciously cloak its browser extensions, circumventing typical scrutiny. The attackers remodel the browser’s Secure Preferences to ensure their harmful extension appears legitimate, even without user consent. This approach, originally outlined in 2025 by Synacktiv under the term “The Phantom Extension“, illustrates how attackers can manipulate internal browser settings to deploy malicious tools effectively.
Once activated, the KREMLIN-related extension masquerading under the name AVSync can extract sensitive information, including browser databases, which contain user login details and other private data. The initial infection mechanism involves executing deceptive JavaScript files, posing as invoices or receipts, effectively compromising the systems of unsuspecting victims.
Mitigation Efforts and Ongoing Threat
Elastic’s discovery provided not only insights into the workings of KREMLIN but also methodology to slow down its operations. By registering an unassigned domain that KREMLIN checked periodically to avoid detection, Elastic was able to divert infected systems, revealing at least 1,515 machines affected, with the vast majority situating in Brazil. Although this strategy momentarily disrupted the malware’s functionality, affected devices remain compromised until further remediation occurs.
Throughout its operational history, KREMLIN has evolved, transitioning from earlier iteration tools like PULSAR RAT to more robust additions such as REMCOS RAT as well as the deployment of its bespoke browser extensions. A comprehensive network analysis led to the discovery of a single Ethereum wallet managing the contracts, indicating substantial financial activity correlating with the malware’s deployment history.
Security teams are urged to utilize the insights provided by Elastic, including the public repository of indicators of compromise (IOCs) to assess and mitigate the risks posed by this ongoing campaign targeting Brazilian users, particularly within the financial sector.