ETH Contract Dead Letter Box: Bank Trojan Replaces Its Own C2

The bank trojan in Brazil has finally gone real—Elastic calls it KREMLIN / REF9334. At least since May 2025, it tricks you into running a piece of JS with fake bank documents, then installs an extension into Chrome/Edge that you never agreed to.

The brutal part: the C2 isn’t hard-coded. The payload asks the Ethereum contract dead letter box—when a parameter changes, the download URL and the next-step domain change accordingly, and if the server can’t be shut down, this whole line keeps working. The extension disguises itself as “AVSync System Inc.”, alters Secure Preferences to forge integrity checks, and makes the browser treat it as a legitimate load.

After Elastic registered its network canary domain, the callback hosts counted 1,515 machines—nearly 99% in Brazil. You think “putting it on-chain = censorship resistance” is cool, and the bank trojan uses the same idea. Don’t double-click an unknown .js invoice as if it were a legitimate file.