
KREMLIN Brazilian Malware Reuses APT31 Phantom Extension Bypass with Ethereum Smart Contract C2
KREMLIN combines multi-stage JS loaders, SentinelOne sideloading, and Ethereum dead drops to install persistent credential-harvesting extensions on Chrome and Edge. The campaign overlaps technically with prior APT31 methods yet remains focused on Brazilian financial targets. Continued use of public bypass techniques will likely accelerate adoption across both criminal and state actors.
Blockchain-based C2 resolution raises the cost of infrastructure disruption while the SentinelOne abuse pattern signals likely expansion to other endpoint products. Defenders should monitor for new Ethereum contract updates and extension ID ndpbidppejfanjbhfgjlohfanbfbklff activity on corporate browser profiles.
Elastic Security Labs: KREMLIN Ethereum resolver will publish at least two new C2 domains before 31 December 2026 if current operational tempo holds.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)
- [2]Supporting Source(https://www.elastic.co/security-labs/ref9334-kremlin)