KREMLIN Malware Uses Ethereum to Target 1,515 Systems

KREMLIN malware has infected at least 1,515 systems, mainly in Brazil, in a banking campaign that uses Ethereum smart contracts to update command-and-control infrastructure. Elastic Security Labs tracked seven campaigns under REF9334 since May 2025, while SlowMist highlighted the blockchain component in a September 2026 alert. The KREMLIN malware campaign uses Ethereum contracts as an on-chain dead-drop resolver. Infected devices read configuration data from the contracts to locate payloads and attack servers. Operators can therefore change infrastructure without modifying the malware. Elastic identified three related Ethereum contracts, with the latest remaining active when its report was published. The malware spreads through JavaScript files disguised as bank receipts, invoices and business documents. It modifies Chromium Secure Preferences to install unauthorized extensions on Chrome and Microsoft Edge. The extensions can collect browser credentials, cookies, session tokens, stored form data and other sensitive information. Researchers recorded 1,515 infected hosts, and 98.75% were located in Brazil. The campaign impersonated Brazilian financial brands and used Portuguese-language lures. Elastic also traced 82 USDT transfers linked to the wallet used to deploy and update the malicious contracts, involving about 20,778.97 USDT received and 19,016.96 USDT sent. The operation does not indicate a compromise of Ethereum itself. Instead, it shows how public blockchains can provide resilient malware infrastructure. The campaign’s name refers to the malware author’s handle, not evidence of Russian involvement.
Neutral
The direct market impact is likely neutral. The incident uses Ethereum as an infrastructure and configuration layer, not as a vulnerability or attack on Ethereum’s consensus, wallets or transaction settlement. As a result, it does not materially change ETH’s fundamental network security or supply-demand outlook. In the short term, traders may see limited volatility in ETH or related cybersecurity tokens if the report gains broad media attention. However, past malware campaigns that used public blockchains, including similar smart-contract-based command infrastructure, generally produced little sustained impact on major cryptocurrency prices. The more immediate effect is operational: exchanges, banks and custodians may increase monitoring of suspicious contracts and blockchain-linked wallets. The 82 USDT transfers and the identification of active contracts could support further law-enforcement action, wallet attribution or asset freezes. Such measures might briefly raise concerns about illicit use of crypto infrastructure, but they are unlikely to affect the wider market unless investigators uncover a major exchange compromise or systemic vulnerability. Long term, the case may reinforce demand for blockchain analytics, endpoint security and wallet-screening tools. It could also prompt stricter compliance measures for stablecoin transfers and smart-contract interactions. Those developments may increase regulatory scrutiny, but the evidence presented does not justify a bullish or bearish trading signal for ETH. Traders should monitor follow-up disclosures, exchange exposure and any signs of broader infections rather than treat the malware report as a directional crypto catalyst.