Security researchers have uncovered a large banking malware campaign called KREMLIN that uses Ethereum smart contracts to update its attack infrastructure.
Elastic Security Labs said it tracked more than 1,500 infected systems, with the overwhelming majority located in Brazil.
The malware campaign combines malicious browser extensions, credential theft and blockchain-based command infrastructure, allowing attackers to change server locations without modifying the malware already installed on victims’ devices.
Researchers have followed the operation across seven separate campaigns dating back to May 2025.
KREMLIN malware mainly targets Brazilian banking users
KREMLIN has primarily targeted users of Brazilian banks and financial services.
Elastic said around 98.75% of the 1,515 infected systems it identified were located in Brazil.
The malware has used Portuguese-language files and fake documents impersonating Brazilian financial institutions.
Brands appearing in campaign material included Banco do Brasil, Caixa, Bradesco, Sicoob, C6 Bank, Inter, BTG, Safra, PagBank, PicPay, Santander and Mercado Pago.
Despite the malware’s name, researchers said they found no evidence linking the campaign to Russia.
According to Elastic, the name KREMLIN comes from the malware developer’s online handle rather than any confirmed connection to the Russian government or Russian cyber groups.
Ethereum smart contracts help attackers change server locations
One of the most unusual parts of the campaign is its use of Ethereum.
Researchers first observed Ethereum being used by KREMLIN in May 2026.
Instead of directly hosting malware on Ethereum, the attackers use smart contracts as a type of decentralized address book.
The contracts store configuration information that tells infected machines where to find malicious servers, installers and browser extensions.
This means attackers can update infrastructure references stored onchain without changing the malware already running on compromised computers.
For example, if an attacker-controlled domain is blocked or taken offline, the operators can update the smart contract with a new location.
Infected machines can then read that updated information from Ethereum.
Ethereum itself was not hacked
The campaign does not represent a vulnerability in Ethereum.
Researchers did not find evidence that the attackers exploited Ethereum’s consensus mechanism or broke its smart-contract system.
Instead, the operators simply used publicly available blockchain infrastructure as part of their command-and-control setup.
This approach can make malware infrastructure harder to disrupt because data stored on a public blockchain cannot be removed as easily as information hosted on a traditional server.
Similar techniques have appeared in other malware campaigns.
Security researchers have previously found malicious software using Ethereum and BNB Chain smart contracts to retrieve server addresses and attack instructions.
KREMLIN installs malicious Chrome and Edge extensions
KREMLIN also uses malicious browser extensions to steal sensitive information.
Elastic found that the malware can modify configuration files used by Chromium-based browsers such as Google Chrome and Microsoft Edge.
The malware changes the browser’s Secure Preferences data and recreates the integrity values required by the browser.
This can allow a malicious extension to appear properly registered even though the user never approved its installation through an official browser extension store.
The technique allows attackers to gain deep access to browser activity.
Malicious extensions can steal passwords and session data
Elastic analyzed a malicious extension disguised as software called AVSync.
The extension requested access to browser tabs, cookies, stored data and web requests.
Once active, it could collect sensitive information including:
- Saved login credentials
- Browser cookies
- Session tokens
- Stored form information
- Browser storage data
- Information from active web sessions
The malware can also collect the encryption material needed to access protected browser databases.
This makes the campaign particularly dangerous because stolen session cookies and tokens may sometimes allow attackers to access accounts without needing the user’s password again.
Infection begins with malicious files
KREMLIN still requires a victim to execute a malicious file before the attack can begin.
According to Elastic, the attackers distribute JavaScript files disguised as legitimate documents such as bank receipts, invoices or corporate files.
Once a user launches the malicious file, the malware checks the system environment before downloading or activating additional components.
Earlier versions of the campaign distributed PULSAR RAT.
Later versions introduced REMCOS RAT alongside the custom browser extension and Ethereum-based infrastructure.
The malware operators have continued changing their tools over time, suggesting that the campaign is still being actively developed.
Elastic identified 1,515 infected systems
Elastic gained an unusual level of visibility into the campaign after researchers discovered that KREMLIN checked an unregistered internet domain as part of its anti-analysis system.
The malware was designed to contact this domain.
If the domain responded, KREMLIN assumed it was running inside a security sandbox and stopped executing.
Elastic registered the previously unused domain and connected it to infrastructure controlled by the researchers.
As infected systems attempted to contact the domain, Elastic was able to count them.
Researchers recorded 1,515 infected machines, with the total reportedly increasing quickly.
Around 98.75% of those systems were located in Brazil.
Researchers turned KREMLIN’s defense mechanism against it
Registering the domain did more than help Elastic count infected devices.
It also temporarily disrupted part of the attack.
Because the malware interpreted a response from the domain as evidence that it was running inside a security-testing environment, infected systems stopped progressing through the malware chain.
This effectively turned KREMLIN’s own anti-analysis feature against the attackers.
However, Elastic stressed that this did not remove the malware from compromised systems.
The computers remained infected, even though the campaign’s ability to continue operating on those systems was temporarily limited.
That means affected devices still require investigation and cleanup.
Ethereum wallet links multiple stages of the campaign
Blockchain activity also helped researchers connect different parts of the operation.
Elastic identified one Ethereum wallet that was used to deploy and update the malicious smart contracts associated with KREMLIN.
The wallet had been active for more than a year before researchers identified the Ethereum-linked malware branch.
Between June 19, 2025 and Aug. 24, 2026, researchers identified 82 USDT transactions involving the wallet.
The wallet received approximately 20,778.97 USDT and sent roughly 19,016.96 USDT during that period.
However, Elastic said it could not confirm that every transaction was directly related to malware development or campaign funding.
Transaction timing points toward Brazil, but does not confirm attribution
Researchers also studied when transactions involving the Ethereum wallet occurred.
Much of the activity took place during business hours in the UTC-3 time zone used by São Paulo.
This created another possible connection to Brazil.
However, Elastic did not present this as definitive proof of where the malware operators are located.
The researchers described Brazil as a plausible location based on the available evidence rather than a confirmed attribution.
Other indicators also support the campaign’s Brazilian focus, including Portuguese-language content, local banking brands and the geographic distribution of infected systems.
Blockchain infrastructure makes malware harder to disrupt
KREMLIN demonstrates how cybercriminals can use decentralized infrastructure without attacking the blockchain itself.
Traditional malware command servers can often be blocked, seized or taken offline.
A smart contract on a public blockchain is much harder to remove.
Attackers can therefore use blockchain data to store changing infrastructure details while keeping their original malware unchanged.
Even if defenders shut down one malicious domain, the attackers may simply update the blockchain-based configuration with another address.
This does not make the attack impossible to stop, but it can complicate traditional methods used to disrupt malware infrastructure.
Security teams can search for KREMLIN indicators
Elastic has published technical indicators that security teams can use to search for signs of compromise.
These indicators can be checked against endpoint logs, browser activity and network telemetry.
Elastic mapped the campaign to several MITRE ATT&CK techniques covering areas such as:
- Malware execution
- Persistence
- Credential theft
- Browser extension abuse
- Command-and-control activity
- Data exfiltration
Organizations operating in Brazil, particularly those working with financial institutions, may have a higher reason to review their systems for related indicators.
What the KREMLIN campaign shows
The KREMLIN campaign highlights a growing challenge for cybersecurity teams: attackers are increasingly using legitimate decentralized technologies as part of malicious infrastructure.
Ethereum itself was not compromised.
Instead, the attackers used smart contracts as a reliable method for distributing updated configuration data to infected devices.
Combined with malicious Chrome and Edge extensions, credential theft and remote-access tools, the approach allowed KREMLIN to maintain a flexible attack infrastructure targeting Brazilian banking users.
Elastic’s intervention temporarily weakened part of the campaign and provided valuable insight into its scale, but compromised systems still need to be cleaned.
The discovery also shows how blockchain transaction data can help investigators connect separate malware campaigns and follow attacker infrastructure over time.









































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































