Aeternum C2 is a turnkey botnet loader identified in late 2025 that uses the Polygon blockchain as part of its command-and-control architecture. It has been advertised on underground forums as a low-cost service, indicating availability to a broad range of criminal operators rather than attribution to a specific state-backed intrusion set. Its defining characteristic is the use of blockchain-backed infrastructure to support resilient command-and-control, aligning it with a broader trend in which malware operators use public ledgers and smart-contract data to make disruption more difficult than with conventional domain- or IP-based infrastructure. High-confidence reporting supports its role as a loader and botnet-enablement capability, but does not provide corroborated detail on specific victim sectors, countries, follow-on payload families, or a distinct operator identity beyond the Aeternum C2 name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.