KREMLIN malware uses Ethereum to update attack servers: Malware
KREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil.
StatusUnder review
Reported lossUnavailable
ChainEthereum
Confidence55%
Evidence boundary
Confidence describes the coverage of the available evidence. It is not a safety rating and does not guarantee that a protocol or asset is safe.
Sources
Record history
First seen: 2026-09-16T12:26:23.000Z. Last updated: 2026-09-16T14:51:35.167Z. Revision: 1.