A newly uncovered banking malware campaign is using Ethereum smart contracts to update its attack infrastructure, allowing operators to change command servers and malicious payload locations without modifying the malware already installed on victimsโ devices.
Security researchers at Elastic Security Labs identified the operation, tracked as REF9334, and have been monitoring its activity since May 2025. The campaign primarily targets users in Brazil through malicious files and browser extensions designed to steal credentials, cookies, session tokens and other sensitive browser data.
Elastic identified the malware toolkit as KREMLIN and tracked seven campaigns over roughly 15 months. Researchers observed 1,515 infected systems contacting infrastructure controlled for research purposes, with 98.75% of the identified systems located in Brazil.
Ethereum Used to Change Malware Infrastructure
The campaign began using Ethereum smart contracts in May 2026. According to Elastic, the attackers use the contracts as an on-chain configuration system that stores information pointing infected machines toward external servers and files.
This approach allows the operators to update infrastructure references by changing values stored in the smart contracts while leaving the original malware unchanged. Researchers identified three Ethereum contracts associated with the campaign, with the latest contract remaining active when Elastic published its findings.
The use of Ethereum does not indicate a vulnerability or exploit within the Ethereum network itself. Instead, the attackers are using publicly accessible blockchain data as a mechanism for distributing configuration information to infected systems.
Malicious Chrome and Edge Extensions
The malware also uses a technique designed to install malicious extensions on Chromium-based browsers without requiring normal user approval.
Elastic found that KREMLIN modifies Chrome and Microsoft Edge’s Secure Preferences data and regenerates integrity values used by the browsers. This can allow an unauthorized extension to appear as properly registered within the browser.
One extension analyzed by researchers was disguised as software called AVSync. It requested access to browser tabs, cookies, storage and web requests, allowing it to collect information from active browsing sessions.
The malware can also access stored login information, cookies and form data. Researchers said the campaign uses additional components to obtain the encryption material required to access protected browser information.
Brazil Remains the Primary Target
The campaign relies on social engineering to initiate infections. Malicious JavaScript files were disguised as bank receipts, invoices and corporate documents. Researchers identified references to several Brazilian financial institutions, including Banco do Brasil, Caixa, Bradesco, Santander and Mercado Pago.
Elastic’s analysis also found Portuguese-language filenames and messages throughout the campaign, further supporting Brazil as the primary target.
The name KREMLIN does not indicate a Russian connection. Elastic specifically said it found no evidence linking the operation to Russia. The name was derived from the malware author’s online handle.
Researchers Track Crypto Activity
Blockchain activity provided additional information about the campaign. Elastic identified an Ethereum wallet used to deploy and update the malicious smart contracts.
Researchers traced 82 USDT transfers associated with the wallet between June 2025 and August 2026. The transactions totaled approximately 20,779 USDT received and 19,017 USDT sent, although Elastic noted that the transfers could not conclusively be classified as funding for malware development.
The findings highlight another use of public blockchain infrastructure in cyberattacks, with attackers using smart contracts as a persistent channel for updating malware configuration.
