← BACK TO FEED
TAG

banking malware1 article

KREMLIN Malware Uses Ethereum Smart Contracts and Rogue Browser Extensions to Drain Brazilian Bank Accounts

KREMLIN is a Brazilian banking malware ecosystem, tracked by Elastic Security Labs since at least May 2025, that uses multi-stage JavaScript loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data from victims impersonating customers of over a dozen Brazilian banks. A key feature of the operation is its use of Ethereum smart contracts to dynamically update command-and-control infrastructure, making it highly resilient to disruption. The malicious browser extensions bypass Chromium's security mechanisms to harvest cookies, screenshots, and browsing data, with over 1,500 infected systems identified — more than 98% located in Brazil.

16 Sept 2026