logo

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

ID: 91c84b88-deb7-5a91-aaec-0a4982ba5baf

STIX ID: report--91c84b88-deb7-5a91-aaec-0a4982ba5baf

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang

...
...

This report analyzes the Aeternum botnet, a novel malware family that retrieves encrypted and plaintext C2 commands from Polygon blockchain smart contracts to drive a multi-stage infection chain. It documents three samples—a C++ loader that fetches payloads and exfiltrates via Telegram, a PyInstaller package that drops XWorm RAT and an XMRig miner, and a Python sample with blockchain-based domain resolution—providing behavioral and static analysis, decryption methods, and extensive IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.