logo

Aeternum Loader: When your C2 lives forever

ID: caccfae7-690b-56fc-8bb6-b943aeb5dab8

STIX ID: report--caccfae7-690b-56fc-8bb6-b943aeb5dab8

Feed Name: Ctrl-Alt-Int3l

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-19

Author: Ctrl-Alt-Int3l

...
...

Aeternum C2 BotNet Loader — CtrlAltIntel examined a malware loader that uses Polygon smart contracts to publish encrypted C2 commands; by accessing an exposed operator panel and reversing the JavaScript/contract implementation, researchers derived the PBKDF2/AES-GCM scheme (keyed from the contract address), decrypted historical commands across dozens of identical contracts, enumerated related contracts and creator addresses (including LenAI), and published 209 decoded commands and IOCs revealing payload hosting and deployment attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.