Skip to main content
KREMLIN malware uses Ethereum for server updates
Image for illustrative purposes only. Not a real photo.

KREMLIN malware uses Ethereum for server updates

Share
  • KREMLIN malware uses Ethereum (CRYPTO:ETH) smart contracts to update its attack infrastructure.
  • Elastic Security Labs found 1,515 infected systems, with 98.75% located in Brazil.
  • The malware targets Brazilian banking users through malicious browser extensions and multi-stage attacks.

Elastic Security Labs has tracked KREMLIN malware across seven campaigns over 15 months.

The malware uses Ethereum (CRYPTO:ETH) smart contracts to update attack servers without changing its core code.

The campaign mainly targets Brazilian banking users with fake documents and payment service lures.

The attack starts with malicious JavaScript files disguised as invoices, bank documents or company files.

The malware installs additional components and creates a scheduled Windows task for persistence.

It then queries an Ethereum smart contract for URLs linked to its malware components and payloads.

Elastic found 1,515 infected systems, with 98.75% located in Brazil, during its analysis of the campaign.

Despite its KREMLIN name, Elastic found no evidence linking the malware operation to Russia.

At the time of reporting, Ethereum price was $2,435.60.


Frequently asked questions