Aeternum Botnet Blockchain-Based C2 Operations and Communications
Score: 9/10

Aeternum Botnet Blockchain-Based C2 Operations and Communications

The Aeternum botnet utilizes the public Polygon blockchain as a decentralized command-and-control infrastructure to distribute XWorm, XMRig, and data-stealing payloads.

Executive Summary

Aeternum is an evolving C++ botnet and loader that leverages the Polygon blockchain for its command-and-control (C2) operations, effectively bypassing traditional DNS and IP-based blocking. Operated by a threat actor known as LenAI, the botnet queries immutable smart contracts to retrieve encrypted instructions and payload URLs. This decentralized architecture provides high resilience against law enforcement takedowns and reduces infrastructure costs.

The infection chain is multi-staged, often beginning with social engineering lures like fake DBeaver installers. Once execution is established, the malware performs environment checks and achieves persistence via Windows Startup shortcuts. Subsequent activity involves the deployment of XWorm RAT, XMRig cryptocurrency miners, and custom information stealers that target over 55 browser extensions and multiple desktop wallets, exfiltrating data via the Telegram API or dedicated C2 servers.

Key Details

Threat Name

Aeternum Botnet

Affects

—

Adversary

LenAI

Malware/Tools

Aeternum, XWorm, XMRig, ZingoStealer

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources