SlowMist disclosed KREMLIN, a Brazilian banking malware operation active since May 2025, which uses multi-stage loaders and malicious browser extensions to steal credentials and data. The malware bypasses Chromium security mechanisms and leverages Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, with 1,515 infected hosts primarily in Brazil.