unit42.paloaltonetworks.com • 8h
Aeternum: Exploiting Polygon Blockchain for Decentralized C2 Operations
Aeternum is a persistent botnet loader that utilizes the Polygon blockchain to implement a decentralized Command and Control (C2) architecture. By embedding encrypted commands and payload locations within smart contracts and blockchain transactions, the threat actor eliminates the need for centralized C2 servers. This methodology renders standard mitigation techniques, such as DNS sinkholing or IP blocking, ineffective. The malware leverages "ClickFix" techniques for C2 domain distribution and blends malicious signaling with legitimate Web3 traffic, ensuring high resilience against law enforcement and security vendor takedown efforts.