Executive Summary
Aeternum is an evolving C++ botnet and loader that leverages the Polygon blockchain for its command-and-control (C2) operations, effectively bypassing traditional DNS and IP-based blocking. Operated by a threat actor known as LenAI, the botnet queries immutable smart contracts to retrieve encrypted instructions and payload URLs. This decentralized architecture provides high resilience against law enforcement takedowns and reduces infrastructure costs.
The infection chain is multi-staged, often beginning with social engineering lures like fake DBeaver installers. Once execution is established, the malware performs environment checks and achieves persistence via Windows Startup shortcuts. Subsequent activity involves the deployment of XWorm RAT, XMRig cryptocurrency miners, and custom information stealers that target over 55 browser extensions and multiple desktop wallets, exfiltrating data via the Telegram API or dedicated C2 servers.
