Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

rpc.polygon-zkevm.gateway.fm

TLP:CLEAR
Active

Domain

Description

Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

Sightings (0)

No sightings recorded yet

Details

Name / Label
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Pattern Type
STIX
Confidence
75%
Valid From
Aug 11, 2026 12:01
Total Sightings
0
Added
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of rpc.polygon-zkevm.gateway.fm

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.