THE article from Palo Alto Networks discusses the Aeternum botnet, a C++ loader that utilizes the Polygon blockchain for its command-and-control operations. Unlike traditional centralized systems, Aeternum's threat actors engage with the blockchain through smart contracts to send encrypted commands. This decentralized approach enhances resilience against takedown attempts by law enforcement.
The analysis covers three malware cases associated with Aeternum: 1) the Aeternum loader, which creates a persistent presence and communicates through the Polygon blockchain; 2) a combination of XWorm RAT and XMRig cryptocurrency miner; and 3) a Python-based variant that can fetch new C2 domains.
The report emphasizes Aeternum's effective evasion techniques, weak encryption practices, and reliance on platforms like Telegram for data exfiltration, demonstrating a sophisticated evolution of malware that leverages blockchain technology.