The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Executive Summary
Unit 42’s analysis of the Aeternum botnet loader reveals a novel use of the Polygon blockchain to host decentralized command‑and‑control (C2) infrastructure. The loader pulls instructions from smart contracts, enabling the botnet to evade traditional detection and maintain persistence. Payloads are executed directly from the blockchain, allowing the threat actor to update malware, distribute new modules, and orchestrate attacks without relying on conventional servers.
Intelligence Metadata - Source Publisher: Unit 42 (Palo Alto) - Published Date: 2026-08-10T22:00:02+00:00 - Category: research
"We all have problems. The way we solve them is what makes us different."
— Unknown
Source: Unit 42 (Palo Alto)