logo

Aeternum botnet hides commands in Polygon smart contracts

ID: c209a6ed-3501-5438-b3d1-985a597985af

STIX ID: report--c209a6ed-3501-5438-b3d1-985a597985af

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Qrator Labs uncovered Aeternum, a C++ botnet loader that uses Polygon smart contracts for immutable, decentralized command-and-control; operators publish commands via blockchain transactions, infected hosts read and execute them, and the malware is sold as a ready-made product or source code, featuring anti-VM checks and builtin AV-scanning to evade detection—making takedown and disruption far more difficult and increasing potential for large-scale abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.