cognitive cybersecurity intelligence

News and Analysis

Search

Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

Aeternum is a new botnet loader designed to resist takedowns. It stores instructions on Polygon, a public blockchain, creating a widely replicated control channel that is difficult to remove.

The malware reaches Windows systems through several routes. Investigators found a packed loader, an XWorm and XMRig package, and Python code in a fake DBeaver installer.

Once launched, the samples check for virtual machines and security tools, establish startup persistence, then seek their next instructions.

Unit 42 researchers identified the campaign as an evolving operation that uses Polygon smart contracts for command and control.

Their analysis links three samples through shared code patterns and contract functions, showing how the same service can direct loaders, spyware, data theft and cryptocurrency mining without relying on a single conventional server.

Unit42 researchers said in a report shared with Cyber Security News (CSN) that the impact is broader than one malicious file. Aeternum can deliver further malware, collect host and wallet data, and send it through Telegram or another control server.

During the study, researchers recorded more than 29,000 detection events by June 4, 2026, evidence that blockchain-backed control is a practical criminal tool.

Aeternum Botnet Uses Polygon Smart Contracts

Aeternum uses a smart contract as a public noticeboard for infected devices. That means responders cannot rely on a single hosting provider or registrar to cut the botnet off.

They must identify the infected device and stop its local activity, even when the control lookup remains publicly available and threatens to reach other systems quickly.

Aeternum C2 blockchain HTTP communication (Source – Unit42)

Each bot queries Polygon remote procedure call services and reads a contract value containing either a command or a destination for the next stage. Blocking a web host or domain does not remove those on-chain instructions.

The loader uses a domain-retrieval function to obtain an XOR key and an encrypted command-and-control domain.

Operators can use an administrative function to replace the stored destination, redirecting existing infections.

That design resembles the blockchain resolver technique discussed in SharkStealer command infrastructure analysis, but Aeternum applies it across several malware components.

One analysed loader unpacked itself, copied files into AppData and created a Windows Startup shortcut before contacting Polygon. It then fetched benign-looking and malicious files from code repositories.

The DLL collected system information and prepared it for Telegram-based transfer, demonstrating how a public blockchain lookup can connect quietly to ordinary web services used for delivery and data movement.

A weak encryption implementation also gave defenders an opening. The contract address and returned payload were enough for researchers to recover encrypted instructions, including download commands.

Decryption script run on an encrypted Aeternum blockchain value (Source – Unit42)

Teams should hunt for unusual Polygon JSON-RPC traffic, then correlate it with Startup shortcuts, downloads and Telegram API activity.

Payloads Turn Access Into Theft

A second sample used the same on-chain lookup to obtain a Pastebin location holding XMRig configuration.

It dropped an XWorm remote-access tool and a miner, while a later stage sent encrypted victim data to an external address.

Its follow-on capability resembles recent XWorm malware activity, where credential theft and session hijacking also feature prominently.

The Python source code points to a targeted operation. It impersonates a DBeaver installer, rejects lightweight analysis environments, creates persistence and injects code into a signed Windows binary before security monitoring initializes.

Malicious DLL file hosted on GitHub (Source – Unit42)

It also includes routines aimed at credentials from more than 55 cryptocurrency browser extensions and 10 desktop wallets.

Telegram supports both reconnaissance and exfiltration in this branch, while junk-filled JSON is intended to make traffic patterns harder to recognize.

Attackers therefore need not maintain every piece of infrastructure themselves. Similar abuse of public services has appeared in Paste platform XWorm campaigns, reinforcing the value of monitoring behavior rather than trusting a service by name.

The blockchain-based botnets are likely to continue, so the defenders should investigate the indicators below, restrict unapproved executables, and review telemetry for contract queries preceding downloads, injection or data transfers.

They should also alert on process launches from user-writable folders and verify outbound connections made immediately after a blockchain lookup. Operators can rotate destinations without rebuilding the botnet.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionSHA256 hash5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898Aeternum C loader executableSHA256 hash1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505Malicious downloaded DotNetZip.dllFilenameDotNetZip.dllMalicious payload executed by the loaderFilenameputty.exeBenign file downloaded for testing or stagingFilenameWmiFrameworkAPIKEYwmsnetrandomvalue.lnkStartup link for persistenceFilenamewmiframework.exe, ZrvEsJQzWQ.exe, STAAAAAS.exeSupporting binariesDomainapi.telegram.orgTelegram API endpoint used in DLL activityRepositoryhxxps://github[.]com/lencodRepository hosting malicious file artifactsRepositoryhxxps://github[.]com/Mash3DoRepository hosting malicious file artifactsTelegram ID-4991861036Hard-coded chat ID for Telegram C2 botTelegram token8305917772AAHAou…Hard-coded Telegram bot API tokenContract address0x04E25a563f159308FC3E15fE9Ccc9D2CF623D0ccSample 1 Polygon smart contractContract address0x16dA95799CB8aB203f83e01AFC030B1217198Da4Sample 1 Polygon smart contractContract address0x1D50703722729dD68e89D819F69eFc5Fb206bBe7Sample 1 Polygon smart contractContract address0x27c7c36981c1ed5cFA2DCDb4B43C27A6BaF6bEa8Sample 1 Polygon smart contractContract address0x4dcE7d4b1229F3705BDB70341484cF2EEE36432eSample 1 Polygon smart contractContract address0x55b4F951d5Ac035C21B170C73C0A930a641b718CSample 1 Polygon smart contractContract address0x6da31EB2A016074ffd5519326573E78E2677E4C8Sample 1 Polygon smart contractContract address0x737791081A398151195a753Fb49f9c1b8bc1fCDBSample 1 Polygon smart contractContract address0x7D2D8A4A6E8D89cf5C151C4f68A521490D9779B0Sample 1 Polygon smart contractContract address0x8d2BaEc2687F59eE1EE7BFd322D33325f5E004eeSample 1 Polygon smart contractContract address0xb3EF2D08Bf25a7daB9d8b98d64E564eA1f6Db924Sample 1 Polygon smart contractContract address0xb8fB2bfb182A172b29C365AD6CF743449975C418Sample 1 Polygon smart contractContract address0xbD6e817Cc510EC3DA5651B5a3AC595d34C0CF1afSample 1 Polygon smart contractContract address0xC37fB924cF5996C9e676BBA399bDfc5F936B3572Sample 1 Polygon smart contractContract address0xC41342908f98E813862EDFe47Ac3af676F8098C9Sample 1 Polygon smart contractContract address0xc7199C1dbCd82c4E002327Aa3EC9158F434a6aCESample 1 Polygon smart contractContract address0xCE476E6f4d83a7a086Cbcdf0FE2E8f221e47e81CSample 1 Polygon smart contractContract address0xD69A36439FffD145ADAcacB94fDe6f8b3546a361Sample 1 Polygon smart contractContract address0xf9438b4E3200AE1611eD3d03310c803FDdf67672Sample 1 Polygon smart contractContract address0xfbC267200f9e5749045f32dbB55BB16615f1CE5FSample 1 Polygon smart contractContract address0xFDB8b139EeacD17ea7c10c256eA77Ba6Dff18D7dSample 1 Polygon smart contractContract address0xFdfB8c4e827c2d053749C8F2f2058548dde0d073Sample 1 Polygon smart contractRPC endpointhxxps://polygon.rpc.hypersync[.]xyzPolygon RPC endpointRPC endpointhxxps://polygon-mumbai.g.alchemy[.]com/v2/demoPolygon RPC endpointRPC endpointhxxps://polygon-mumbai-bor-rpc.publicnode[.]comPolygon RPC endpointRPC endpointhxxps://api.noderpc[.]xyz/rpc-polygon-pos/publicPolygon RPC endpointRPC endpointhxxps://polygon-mumbai.gateway.tenderly[.]coPolygon RPC endpointRPC endpointhxxps://public.stackup[.]sh/api/v1/node/polygon-mainnetPolygon RPC endpointRPC endpointhxxps://gateway.tenderly[.]co/public/polygonPolygon RPC endpointRPC endpointhxxps://polygon-amoy.gateway.tenderly[.]coPolygon RPC endpointRPC endpointhxxps://rpc.poolz[.]finance/polygonPolygon RPC endpointRPC endpointhxxps://gateway.tenderly[.]co/public/polygon-mumbaiPolygon RPC endpointRPC endpointhxxps://api.zan[.]top/polygon-amoyPolygon RPC endpointRPC endpointhxxps://endpoints.omniatech[.]io/v1/polygon-zkevm-testnet/publicPolygon RPC endpointRPC endpointhxxps://rpc.polygon-zkevm.gateway[.]fmPolygon RPC endpointRPC endpointhxxps://polygon-pokt.nodies[.]appPolygon RPC endpointRPC endpointhxxps://polygon-amoy.therpc[.]ioPolygon RPC endpointRPC endpointhxxps://rpc.polygonsupernet.public.arianee[.]netPolygon RPC endpointRPC endpointhxxps://public.stackup[.]sh/api/v1/node/polygon-mumbaiPolygon RPC endpointRPC endpointhxxps://polygon-zkevm-mainnet.public.blastapi[.]ioPolygon RPC endpointRPC endpointhxxps://polygontestapi.terminet[.]io/rpcPolygon RPC endpointRPC endpointhxxps://polygon-mainnet.g.alchemy[.]com/v2/demoPolygon RPC endpointRPC endpointhxxps://polygon-zkevm.drpc[.]orgPolygon RPC endpointSHA256 hashf2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27XBinderOutputprotected.exe main sampleSHA256 hash4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5fXWormClient.exe executableSHA256 hash81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9fXMRig miner.exeDomaingulf.moneroocean[.]streamXMRig mining poolWallet address82pNS8tBnvZ5cmV1iU9cXdQmhGz95P18fZpASBrxtaSF1ToTmZtf3HGHrdXMt1Znuu8BLU17koPs2hTXxTajdTviLcgbbAiXMRig Monero walletIP address193.221.200[.]219HTTP C2 exfiltration addressC2 URLhxxps://ekirolegion.duckdns[.]org/api/endpoint.phpC2 contacted by malware linked to exfiltrationContract address0x75cD25791A60ab3451E2d2feB5ec46c6f541C2B8Sample 2 Polygon smart contractSHA256 hashea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2Python script sampleStaging domaindownload.sftp-api-group-wechat[.]comStaging domain for malware componentsC2 domainupdate.constant-path[.]xyzDomain retrieved from contractC2 domainupdate-launcher[.]xyzDomain retrieved from contractC2 domaintest-steve[.]cyouDomain retrieved from contractTelegram bot token7356125890AAF5ncBIc2pJrEfYPAmy2g9YS7B5NjmtwTcTelegram bot token for exfiltration C2Telegram chats-1002535992165, -1002144122983Telegram chat IDsContract address0xb0874252a7359AA701F3F144A1f03A6e0DA8aE6DSample 3 Polygon smart contractXOR keyhelo1C2 XOR keyXOR keym7rYpry3Domain-decryption XOR keyPersistencePythonLauncher-.lnkWindows Startup shortcutInjected processdpapimig.exeSigned binary used for Early Bird APC injectionDisguised binaryWmiPrvSE.exeDisguised binaryFunction selector0xb68d1809Shared getDomain function selectorFunction selector0xb249cd2dAdministrative updateDomain selectorFunction selector0xf851a440Administrative function auto-getter selectorOperator address0xcaf2c54e400437da717cf215181b170f65187abfLenAI primary smart contract addressC2 domainhxxps://cdnjsdelivr[.]beerNew C2 domain pushed through an updateDomain transaction

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2 appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts