The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted instructions to infected devices. The botnet employs various techniques, including virtual machine detection and antivirus scanning, to evade detection. Palo Alto Networks researchers have identified three malware samples associated with Aeternum, including a loader, a Python-based C2 agent using the Telegram API, and a blended threat combining XWorm RAT, XMRig, and a data exfiltration tool. The Aeternum loader uses a weak encryption scheme based on a self-salting password, making it vulnerable to decryption with known variables. The malware downloads legitimate files like PuTTY to test its functionality and exfiltrates collected information via Telegram.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
