Security researchers have traced more than 1,500 KREMLIN malware infections after uncovering a Brazilian banking campaign that uses Ethereum smart contracts to update attack infrastructure and malicious browser extensions to steal credentials and session data.