news.mlab.sh
Back to the feed
threat-intel

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

High
Image: Palo Alto Unit 42
Summary

Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted instructions to infected devices. The botnet employs various techniques, including virtual machine detection and antivirus scanning, to evade detection. Palo Alto Networks researchers have identified three malware samples associated with Aeternum, including a loader, a Python-based C2 agent using the Telegram API, and a blended threat combining XWorm RAT, XMRig, and a data exfiltration tool. The Aeternum loader uses a weak encryption scheme based on a self-salting password, making it vulnerable to decryption with known variables. The malware downloads legitimate files like PuTTY to test its functionality and exfiltrates collected information via Telegram.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.