{"id":72,"date":"2026-02-26T22:38:47","date_gmt":"2026-02-26T22:38:47","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=72"},"modified":"2026-02-26T22:38:47","modified_gmt":"2026-02-26T22:38:47","slug":"aeternum-c2-botnet-stores-encrypted-commands-on-polygon-blockchain-to-evade-takedown","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=72","title":{"rendered":"Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiQlH8RQUmcg8IWqV76NL0o4uRe86gJ6kxLV3DRYppBAVrfFR_gMPQBFn6GIl2jd9ZgzsuwRGAGTVUbaWCj795-XZ8I3eSBDLz6Q_0w4Alef6GNA3NtpK4po_WVC6p9o4aNVHqgCAEb3a7CqL_x7oBGWQ7N4z0IMyzOX3aZoI_TUZenfdAm0LZojDIkumG0\/s1700-e365\/botnet.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new botnet loader called <strong>Aeternum C2<\/strong> that uses a blockchain-based command-and-control (C2) infrastructure to make it resilient to takedown efforts.<\/p>\n<p>\u00abInstead of relying on traditional servers or domains for command-and-control, Aeternum stores its instructions on the public Polygon blockchain,\u00bb Qrator Labs <a href=\"https:\/\/qrator.net\/blog\/details\/Exploring-Aeternum-C2\/\" rel=\"noopener\" target=\"_blank\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>\u00abThis network is widely used by decentralized applications, including Polymarket, the world&#8217;s largest prediction market. This approach makes Aeternum&#8217;s C2 infrastructure effectively permanent and resistant to traditional takedown methods.\u00bb<\/p>\n<p>This is not the first time botnets have been found relying on blockchain for C2. In 2021, Google said it took steps to disrupt a botnet known as Glupteba that uses the Bitcoin blockchain as a backup C2 mechanism to fetch the actual C2 server address.<\/p>\n<p>Details of Aeternum C2 first emerged in December 2025, when Outpost24&#8217;s KrakenLabs <a href=\"https:\/\/x.com\/KrakenLabs_Team\/status\/1998330973461622894\" rel=\"noopener\" target=\"_blank\">revealed<\/a> that a threat actor by the name of LenAI was advertising the malware on underground forums for $200 that grants customers access to a panel and a configured build. For $4,000, customers were allegedly promised the entire C++ codebase along with updates.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sse-customer-awards-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5Ij_-TeqFMEsRFzgRRFzSRlVK6oHCncN_eJ2fkOdsA_1tN9HQbAlEEife2Z2JUt1lPv4st5n9KZP84jGEYY9Up6BQ7QE-N5rs6OhzL5thxGzVxnMx3JH9cGRLi9S5Kl-iV5PgjBeTdkBLnv_inF8UUAo88iqdmgJuPIc_6qiPyUMXwFyZWbZvkZkcRXSw\/s728-e100\/gartner-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A native C++ loader available in both x32 and x64 builds, the malware works by writing commands to be issued to the infected host to smart contracts on the Polygon blockchain. The bots then read those commands by querying public remote procedure call (RPC) endpoints.<\/p>\n<p>All of this is managed via the web-based panel, from where customers can select a smart contract, choose a command type, specify a payload URL and update it. The command, which can target all endpoints or a specific one, is written into the blockchain as a transaction, after which it becomes available to every compromised device that&#8217;s polling the network.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abOnce a command is confirmed, it cannot be altered or removed by anyone other than the wallet holder,\u00bb Qrator Labs said. \u00abThe operator can manage multiple smart contracts simultaneously, each one potentially serving a different payload or function, such as a clipper, a stealer, a RAT, or a miner.\u00bb<\/p>\n<p>According to a <a href=\"https:\/\/ctrlaltintel.com\/threat%20research\/Aeternum-Part-1\/\" rel=\"noopener\" target=\"_blank\">two-part research<\/a> published by <a href=\"https:\/\/ctrlaltintel.com\/threat%20research\/Aeternum-Part-2\/\" rel=\"noopener\" target=\"_blank\">Ctrl Alt Intel<\/a> earlier this month, the C2 panel is implemented as a Next.js web application that allows operators to deploy smart contracts to the Polygon blockchain. The smart contracts contain a function that, when called by the malware via the Polygon RPC, causes it to return the encrypted command that&#8217;s subsequently decoded and run on the victim machines.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQh_BU2qZgAMPAaHWPZvrCPcPyObbJCdv76tTa_B3jlKu1Bj73xL4DEniUgRMYs5EFkAL01Cx2nN1OoEUPWg2rhLfw8RsJcJ5tmCMhM6y4QwFxLIR3J2zdKeqYrIVKDPIiE6E30I16nZlUnsMXmawGneCbyo3IrxfNrbTuppvw0lScE9pTgAwQUWKy5-40\/s1700-e365\/botnet.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQh_BU2qZgAMPAaHWPZvrCPcPyObbJCdv76tTa_B3jlKu1Bj73xL4DEniUgRMYs5EFkAL01Cx2nN1OoEUPWg2rhLfw8RsJcJ5tmCMhM6y4QwFxLIR3J2zdKeqYrIVKDPIiE6E30I16nZlUnsMXmawGneCbyo3IrxfNrbTuppvw0lScE9pTgAwQUWKy5-40\/s1700-e365\/botnet.jpg\" alt=\"\" border=\"0\" data-original-height=\"603\" data-original-width=\"1600\"\/><\/a><\/div>\n<p>Besides using the blockchain to turn it into a takedown-resistant botnet, the malware packs in various anti-analysis features to extend the lifespan of infections. This includes checks to detect virtualized environments, in addition to equipping customers with the ability to scan their builds via <a href=\"https:\/\/kleenscan.com\/index\" rel=\"noopener\" target=\"_blank\">Kleenscan<\/a> to ensure that they are not flagged by antivirus vendors.<\/p>\n<p>\u00abThe operational costs are negligible: $1 worth of MATIC, the native token of the Polygon network, is enough for 100 to 150 command transactions,\u00bb the Czechian cybersecurity vendor said. \u00abThe operator doesn&#8217;t need to rent servers, register domains, or maintain any infrastructure beyond a crypto wallet and a local copy of the panel.\u00bb<\/p>\n<p>The threat actor has since <a href=\"https:\/\/x.com\/KrakenLabs_Team\/status\/2024872751266148544\" rel=\"noopener\" target=\"_blank\">attempted to sell the entire toolkit<\/a> for an asking price of $10,000, claiming a lack of time for support and their involvement in another project. \u00abI will sell the entire project to one person with permission for resale and commercial use, with all &#8216;rights,'\u00bb LenAI said. \u00abI will also give useful tips\/notes on development that I did not have time to implement.\u00bb<\/p>\n<p>It&#8217;s worth noting that LenAI is also behind a second crimeware solution called ErrTraffic that enables threat actors to automate ClickFix attacks by generating fake glitches on compromised websites to induce a false sense of urgency and deceive users into following malicious instructions.<\/p>\n<p>The disclosure comes as Infrawatch published details of an underground service that deploys dedicated laptop hardware into American homes to co-opt the devices into a residential proxy network named DSLRoot that redirects malicious traffic through them.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ztw-hands-on-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhC66R4wPZ8qksTJukqlCCmrHCUX65DnpWW1nKnkOhy0Poe219tacbU6h09qEfUgRHxoObBazf3SVJ4OAd_iVd0EFecj-vskZSfroQ7rh0XyxQd6Ep_zNgqDW95YU4zG1Gpin8rHPK8Rqu_1KV7tf-G-7JJhxOVHhRJDWnj0qfq82uZSAvAG2rxK-Fe5fwd\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The hardware is designed to run a Delphi-based program called DSLPylon that&#8217;s equipped with capabilities to enumerate supported modems on the network, as well as remotely control the residential networking equipment and Android devices via an Android Debug Bridge (ADB) integration.<\/p>\n<p>\u00abAttribution analysis identifies the operator as a Belarusian national with residential presence in Minsk and Moscow,\u00bb Infrawatch <a href=\"https:\/\/infrawatch.com\/blog\/dslroot-us-proxy-investigation\" rel=\"noopener\" target=\"_blank\">said<\/a>. \u00abDSLRoot is estimated to operate roughly 300 active hardware devices across 20+ U.S. states.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi_5cuQvXxB0qIS039_-H61Ow2qWk9NAHQA-5nEGqrrCuJOrznz13MOeeoEyGNQlgNy6jrX4dzxyidu-QY3edVWV4Ir1N8XzLShDCyM1QLOeI4krl9jMEqhuLjX2VY3sJzdNOCDMs9xgq64j3cqtqDYSQL90oeRAqcT7A2DMeeKVjM1t5UU-68LtGRvZNNw\/s1700-e365\/dslr.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi_5cuQvXxB0qIS039_-H61Ow2qWk9NAHQA-5nEGqrrCuJOrznz13MOeeoEyGNQlgNy6jrX4dzxyidu-QY3edVWV4Ir1N8XzLShDCyM1QLOeI4krl9jMEqhuLjX2VY3sJzdNOCDMs9xgq64j3cqtqDYSQL90oeRAqcT7A2DMeeKVjM1t5UU-68LtGRvZNNw\/s1700-e365\/dslr.jpg\" alt=\"\" border=\"0\" data-original-height=\"1414\" data-original-width=\"2000\"\/><\/a><\/div>\n<p>The operator has been identified as Andrei Holas (aka Andre Holas and Andrei Golas), with the service promoted on BlackHatWorld by a user operating under the alias GlobalSolutions, claiming to offer physical residential ADSL proxies for sale for $190 per month for unrestricted access. It is also available for $990 for six months and $1,750 for annual subscriptions.<\/p>\n<p>\u00abDSLRoot&#8217;s custom software provides automated remote management of consumer modems (ARRIS\/Motorola, Belkin, D-Link, ASUS) and Android devices via ADB, enabling IP address rotation and connectivity control,\u00bb the company noted. \u00abThe network operates without authentication, allowing clients to route traffic anonymously through U.S. residential IPs.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of a new botnet loader called Aeternum C2 that uses a blockchain-based command-and-control (C2) infrastructure to make it resilient to takedown efforts. \u00abInstead of relying&hellip;<\/p>\n","protected":false},"author":1,"featured_media":73,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[191,197,192,195,194,198,196,193,199],"class_list":["post-72","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aeternum","tag-blockchain","tag-botnet","tag-commands","tag-encrypted","tag-evade","tag-polygon","tag-stores","tag-takedown"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/72","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=72"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/72\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/73"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=72"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=72"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=72"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}