logo

Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown

ID: a503a0dc-44a3-5231-8f8c-79678b08e5eb

STIX ID: report--a503a0dc-44a3-5231-8f8c-79678b08e5eb

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed Aeternum C2, a native C++ botnet loader that stores encrypted commands in smart contracts on the Polygon blockchain and retrieves them via public RPC endpoints, making the C2 takedown-resistant; the malware includes anti-analysis checks and is being sold on underground forums. The report also links the actor LenAI to another crimeware product (ErrTraffic) and documents a separate underground residential proxy service (DSLRoot) operated by an identified individual, which leverages deployed hardware and ADB-capable Android devices to provide anonymized U.S. residential IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.