KREMLIN Malware Uses Ethereum to Update Attack Servers
13 Articles
13 Articles
KREMLIN malware uses Ethereum to update attack servers
KREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil.
KREMLIN Malware Targets Browser Sessions
A new banking malware tracked as KREMLIN is reported hijacking Chrome and Edge to steal credentials and active session tokens. The activity centers on browser compromise rather than simple password collection, giving operators access...
A Brazilian banking campaign employs Ethereum smart contracts to update malicious servers and distribute extensions capable of stealing credentials, cookies and session tokens.
Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft
Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.In an in-depth report published e…
Bank malware KREMLIN uses Ethereum smart contracts and malicious extensions to hijack Chrome and Edge in Brazil. See how it works.
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium









