Security· ★★★· bearish·

SlowMist: KREMLIN malware updates C2 via Ethereum smart contracts

  • Malware active since May 2025, uses multi-stage loaders and Chrome and Edge extensions
  • Extensions bypass Secure Preferences, HMAC and App-Bound hashes in Chromium
  • C2 addresses and payloads are updated via Ethereum smart contracts
  • 1,515 infected hosts, 98.75% of them in Brazil
Why it matters: It shows a new vector for abusing blockchain to covertly control malware, complicating efforts to block attack infrastructure.
Source: PANews