Researchers detailed Aeternum, a malware ecosystem and botnet loader that replaces traditional command-and-control servers with the Polygon blockchain, allowing infected hosts to retrieve instructions from smart contracts through public JSON-RPC endpoints. Analysis linked multiple samples, including a C++ loader and a Python variant, through shared smart-contract architecture and the selector 0xb68d1809 used to call getDomain(). The malware also employs anti-analysis measures such as virtual-machine detection, debugger checks, and persistence via Windows Startup shortcuts, indicating an effort to survive disruption and evade investigation.
The observed infection chain delivered additional payloads including XWorm and XMRig, while also stealing host data. One sample downloaded a malicious DotNetZip.dll from GitHub and exfiltrated information through the Telegram Bot API using hard-coded bot credentials and chat IDs; another used blockchain-delivered commands to fetch XMRig configuration from Pastebin, deploy a miner and remote-access malware, and send encrypted stolen data to 193.221.200[.]219. Researchers said the linked tooling and operator activity point to an evolving, decentralized malware operation associated with the moniker LenAI.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that it had recorded more than 29,000 detection events مرتبط with the Aeternum campaign by June 4, 2026. The figure indicated the blockchain-backed malware operation was active at meaningful scale in the wild.
Researchers also analyzed a third sample consisting of Python source code that contained Aeternum logic. This variant helped reveal broader infection-chain behavior and fallback logic across the malware ecosystem.
The second sample decrypted and executed an embedded payload, then dropped XWormClient.exe and an XMRig miner executable. It also exfiltrated encrypted data over HTTP POST to 193.221.200[.]219 using a custom routine based on AES-128 ECB with zero padding.
A second analyzed sample, XBinderOutput_protected.exe, queried the Polygon blockchain using Aeternum’s command values and received a plaintext command that decoded to a Pastebin raw URL. That URL returned XMRig miner configuration data for follow-on activity.
The Build.exe sample downloaded a legitimate PuTTY installer and a malicious DotNetZip.dll from GitHub repositories. After execution, the DLL connected to the Telegram Bot API and exfiltrated host information and a screenshot using hard-coded bot credentials and chat identifiers.
One analyzed sample, a UPX-packed Windows PE named Build.exe, was observed polling 22 Polygon smart contract addresses and using the selector 0xb68d1809 to retrieve commands. It established persistence via a Startup shortcut and executed supporting binaries after deobfuscating configuration data.
Researchers analyzed three linked Aeternum samples and found a malware ecosystem that uses Polygon smart contracts and public JSON-RPC endpoints for decentralized command-and-control. The analysis tied together a C++ loader, a second-stage package deploying XWorm and XMRig, and a Python source-code variant through shared smart-contract architecture and operator activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceunit42.paloaltonetworks.com
Open sourceqrator.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.