KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

Brazilian Bank Malware Updates Addresses via Ethereum Smart Contracts

Published September 19, 2026 10:50 PM · 0 views $ETH
Brazilian Bank Malware Updates Addresses via Ethereum Smart Contracts

Kremlin malware has been analyzed for updating its attack infrastructure and malicious code download addresses through Ethereum smart contracts. SlowMist disclosed this malware case. Kremlin targets Brazilian banks by installing malicious extensions on Chrome and Edge browsers to steal login information and session tokens. Elastic Security Labs reported in an official report that related activities have continued since at least May 2025, with seven campaigns identified over a 15-month period. The firm explained that Kremlin maintains infection through scheduled tasks before retrieving payloads and command-and-control (C2) infrastructure addresses from Ethereum smart contracts. Attackers can update the attack infrastructure without redistributing the initial malware by modifying addresses stored in the smart contract.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 브라질 은행 악성코드, 이더리움 스마트컨트랙트로 주소 갱신