Aeternum C2 is a botnet loader using blockchain-based command-and-control hosted on the public Polygon blockchain. It was reported in late 2025 and described by researchers including Qrator Labs, Outpost24 KrakenLabs, Ctrl Alt Intel, and The Hacker News. The malware is a native C++ loader available in x32 and x64 builds and is operated through a web-based management panel, reported by Ctrl Alt Intel as a Next.js application. Operators write commands to Polygon smart contracts, and infected hosts retrieve encrypted instructions by querying public RPC endpoints, then decode and execute them. The panel supports selecting smart contracts, command types, payload URLs, and targeting either all endpoints or specific victims; researchers also noted operators could manage multiple smart contracts simultaneously for different payloads such as clippers, stealers, RATs, or miners.
The malware is positioned as resilient against traditional takedown because its C2 instructions are stored on a decentralized public blockchain rather than conventional servers or domains. Qrator Labs stated that once command transactions are confirmed on-chain they cannot be altered or removed by anyone other than the controlling wallet holder, and that operators need little infrastructure beyond a crypto wallet and a local copy of the panel. Reported operating costs were low, with approximately $1 worth of MATIC sufficient for about 100 to 150 command transactions.
Aeternum C2 includes anti-analysis and evasion features. Reported capabilities include checks for virtualized environments and the ability for customers to scan builds with Kleenscan to reduce antivirus detection. The malware has been described as a turnkey criminal offering and was advertised on underground forums by a threat actor using the name LenAI. Pricing reported in the source material includes $200 for panel access and a configured build, $4,000 for the full C++ codebase with updates, and a later attempted sale of the entire toolkit for $10,000. LenAI was also linked in the reporting to another crimeware tool called ErrTraffic.
The content associates Aeternum C2 with botnet activity and DDoS operations. Qrator Labs reported attackers increasingly used the Aeternum C2 botnet loader in Q1 2026 DDoS activity, and described its Polygon-based C2 as making the botnet harder to dismantle due to its decentralized nature. No specific file hashes, domains, wallet addresses, or other concrete IOCs were provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...a novel botnet loader named Aeternum C2 has emerged, employing a blockchain-based command-and-control (C2) infrastructure..."
4 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A turnkey botnet loader using the Polygon blockchain, marketed cheaply on underground forums to provide resilient decentralized C2 to lower-tier criminals.
A similar blockchain-based command-and-control tool referenced for comparison with Void Botnet. The content provides no further technical detail beyond its use as a comparable decentralized C2 system.
A botnet loader used in DDoS operations that leverages the Polygon blockchain for decentralized command and control, complicating takedown efforts.
A malware loader botnet whose command-and-control is hosted via the public Polygon blockchain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.