Researchers disclosed a new botnet loader, Aeternum C2, that replaces traditional C2 servers/domains with commands written into smart contracts on the public Polygon blockchain, making the infrastructure difficult to disrupt via conventional takedowns. Infected hosts poll the blockchain by querying public RPC endpoints to retrieve instructions, which are issued as blockchain transactions and become effectively persistent once confirmed. The malware is a native C++ loader with both x86 and x64 builds and is operated through a web-based panel that lets an operator choose a contract, select command types, and set payload URLs/targets.
Reporting attributes the tooling to a threat actor known as LenAI, who advertised access to the malware and panel on underground forums (initially around $200) and later attempted to sell the broader toolkit for a higher price (including claims of offering the full codebase at a premium). The loader includes anti-analysis/anti-VM checks and features intended to help evade detection (e.g., build scanning to avoid antivirus flags), while keeping operating costs low (on the order of ~$1 in MATIC for roughly 100–150 command transactions). The technique follows prior precedent of blockchain-assisted botnet C2 (e.g., Glupteba using Bitcoin as a fallback mechanism), but Aeternum’s use of Polygon smart contracts is positioned as a more durable, “permanent” C2 channel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Separate reporting from Infrawatch described DSLRoot, an underground residential proxy service that deploys dedicated laptop hardware in U.S. homes and uses a Delphi tool called DSLPylon to manage modems and Android devices via ADB. The network was attributed to Belarusian national Andrei Holas and estimated to operate about 300 devices across more than 20 U.S. states.
Public reporting detailed that Aeternum is available in 32-bit and 64-bit C++ builds, supports multiple smart contracts for different payloads, and includes features such as anti-VM checks, infection tracking, and Kleenscan-assisted AV evasion. Researchers also noted the low operating cost of issuing commands on Polygon using MATIC.
Qrator Labs, with reporting also citing Ctrl Alt Intel, disclosed that Aeternum stores encrypted bot commands in Polygon smart contracts and has infected hosts retrieve them through public RPC endpoints. The design makes the botnet more resistant to traditional takedown efforts because it avoids reliance on conventional domains or servers.
After marketing Aeternum C2, LenAI later tried to sell the entire project outright for $10,000. Reporting also linked LenAI to a separate crimeware tool called ErrTraffic used to automate ClickFix attacks.
A threat actor using the name LenAI advertised the Aeternum C2 botnet loader on underground forums, offering a web-based control panel and pricing tiers that included access up to full source code. The malware was described as a native C++ loader with anti-analysis and antivirus-evasion features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcectrlaltintel.com
Open sourcectrlaltintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.