Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features
ID: 5912b19c-ea53-54dc-9605-edc280a3e4fb
STIX ID: report--5912b19c-ea53-54dc-9605-edc280a3e4fb
Feed Name: cybersecurityNews.com
The report describes Aeternum C2, a commercially available malware loader that stores its commands in Polygon blockchain smart contracts so bots read instructions via public RPC endpoints. Marketed on underground forums and available as lifetime builds or source code, Aeternum is low-cost to run, includes anti-VM/AV evasion, supports multiple payload functions (clipper, stealer, RAT, miner), and enables persistent, takedown-resistant operations that could power DDoS, credential stuffing, click fraud, proxy abuse, and data theft — shifting defender focus to endpoint detection and traffic filtering rather than infrastructure seizure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
