Aeternum C2
Aeternum C2 is a botnet loader that uses a blockchain-based command-and-control architecture hosted on the public Polygon blockchain, making it more resistant to traditional takedown methods than server- or domain-based C2. Researchers reported that operators write commands into Polygon smart contracts, and infected systems retrieve those instructions through public RPC endpoints. The malware is described as a native C++ loader available in both 32-bit and 64-bit builds and managed through a web-based panel that allows operators to select smart contracts, choose command types, specify payload URLs, and target either all infected endpoints or specific victims. Reported payload/use cases include delivery of malware such as clippers, stealers, RATs, and miners, and the malware has also been referenced as being used in DDoS operations. Anti-analysis and evasion features mentioned in reporting include virtualization checks and the ability for customers to scan builds with Kleenscan to reduce antivirus detection. Qrator Labs stated that the low operating cost of Polygon transactions allows roughly 100 to 150 command transactions for about $1 worth of MATIC. The malware was advertised on underground forums by a threat actor identified as LenAI, with reported pricing ranging from $200 for panel access and a configured build to higher-priced offers for the full C++ codebase; LenAI later attempted to sell the entire toolkit for $10,000. Outpost24 KrakenLabs disclosed details in December 2025, and subsequent reporting by Qrator Labs and Ctrl Alt Intel further described the panel and on-chain command flow. High-confidence associations in the provided content link Aeternum C2 to decentralized botnet activity and increased difficulty of disruption due to its use of Polygon-based smart contracts rather than conventional C2 infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...a novel botnet loader named Aeternum C2 has emerged, employing a blockchain-based command-and-control (C2) infrastructure..."
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A similar blockchain-based command-and-control tool referenced for comparison with Void Botnet. The content provides no further technical detail beyond its use as a comparable decentralized C2 system.
A botnet loader used in DDoS operations that leverages the Polygon blockchain for decentralized command and control, complicating takedown efforts.
A malware loader botnet whose command-and-control is hosted via the public Polygon blockchain.
Command-and-control framework associated with a botnet described as leveraging blockchain infrastructure.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.