unit42.paloaltonetworks.com 8/10/2026, 10:51:19 PM · external

Aeternum Botnet Leverages Polygon Blockchain for C2

Aeternum Botnet Leverages Polygon Blockchain for C2
CyberSIXT Evidence Panel Source marked as original reporting

THE article from Palo Alto Networks discusses the Aeternum botnet, a C++ loader that utilizes the Polygon blockchain for its command-and-control operations. Unlike traditional centralized systems, Aeternum's threat actors engage with the blockchain through smart contracts to send encrypted commands. This decentralized approach enhances resilience against takedown attempts by law enforcement.

The analysis covers three malware cases associated with Aeternum: 1) the Aeternum loader, which creates a persistent presence and communicates through the Polygon blockchain; 2) a combination of XWorm RAT and XMRig cryptocurrency miner; and 3) a Python-based variant that can fetch new C2 domains.

The report emphasizes Aeternum's effective evasion techniques, weak encryption practices, and reliance on platforms like Telegram for data exfiltration, demonstrating a sophisticated evolution of malware that leverages blockchain technology.

View full article

Article by CyberSIXT