SlowMist: KREMLIN malware updates C2 via Ethereum smart contracts
- —Malware active since May 2025, uses multi-stage loaders and Chrome and Edge extensions
- —Extensions bypass Secure Preferences, HMAC and App-Bound hashes in Chromium
- —C2 addresses and payloads are updated via Ethereum smart contracts
- —1,515 infected hosts, 98.75% of them in Brazil
Why it matters: It shows a new vector for abusing blockchain to covertly control malware, complicating efforts to block attack infrastructure.
Source: PANews