๐Ÿ“… Thursday, 17 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Malware KREMLIN Bajak Data 1.515 Nasabah Brasil - Tapi Server Kendalinya Numpang di Ethereum

KREMLIN Malware Hijacks Data of 1,515 Brazilian Users - But Its Control Servers Run on Ethereum

More than 1,515 computers, the vast majority in Brazil, have been infected by a malware operation dubbed KREMLIN targeting banking customers. A technical report by Elastic Security Labs on September 14, 2026, noted that activity from the threat group tracked as REF9334 has been underway since May 2025 via Portuguese-language Microsoft Edge and Chrome browser extensions. Once installed, the malicious program harvests browser credentials, cookies, session tokens, and victims’ sensitive data without warning.

Yet what makes this hacking tactic stand out is not its data-stealing tools, but how the operators conceal their command-and-control servers.

Blockchain as a Censorship-Resistant Server

The attackers began integrating Ethereum into their infrastructure in May 2026. The first smart contract was deployed on May 19, 2026, not to exploit the consensus mechanism, but to store configuration values. This contract functions to direct victims’ computer systems to the location of malicious installer files and extension updates.

Security firm SlowMist issued a separate threat intelligence alert on September 16, 2026, addressing the on-chain components of the attack. Command-and-control operations via blockchain complicate defense efforts for security analysts, as attackers leverage the public ledger as a communication channel that is exceptionally difficult to block using conventional network filtering methods.

Elastic tracked three main Ethereum contracts underpinning the KREMLIN operation. The contract at address 0xCD7360A83E5cdbBbbbcEB0e78748babA6740d07b remained active when the report was published, supported by two secondary addresses: 0x902EDbFECFF38f285Bf26283fB9cEB3700061873 and 0x64Def0A6099c4DE9C413B108EAae85A3C7457615. Over 15 months and across seven attack campaigns, their contract architecture evolved from static configurations into a dynamic key-value system that operators can update at any time.

A Misleading Geographic Label

Although the malware’s name invites assumptions about the hackers’ origins, Elastic’s report found zero evidence of Russian involvement. The name KREMLIN stems solely from a handle or pseudonym used by the author of the code. Their primary focus on Brazil using Portuguese-language lures reinforces that the campaign’s targets are driven by local banking financial profiles rather than geopolitics.

For everyday users, this shift to on-chain tactics carries one clear takeaway. When routine attack instructions hide within public crypto transaction traffic, the most effective defense for consumers is refusing to install browser extensions from unverified sources.

Source: crypto.news.

Read also: Chainflip Network Halted After $736K Exploit - Hacker Used TRON Memo Trick for Double-Spending


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share