SlowMist Reports KREMLIN Malware Using Ethereum Smart Contracts for Infrastructure Updates
SlowMist (SlowMist) has identified that the REF9334 banking malware operation, active since May 2025, utilizes Ethereum (Ethereum) smart contracts as dead-drop resolvers to dynamically update command-and-control endpoints. The KREMLIN malware ecosystem employs multi-stage loaders and malicious browser extensions to steal sensitive data, bypassing security mechanisms in Chrome and Edge. Analysis of the network revealed over 1,500 infected hosts, with the vast majority located in Brazil.
Summaries are written by AI from the original article. Not investment advice.