{"id":11015,"date":"2026-02-28T10:03:39","date_gmt":"2026-02-28T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/28\/researchers-uncover-aeternum-c2-infrastructure-with-advanced-persistence-and-network-evasion-features\/"},"modified":"2026-02-28T10:03:39","modified_gmt":"2026-02-28T10:03:39","slug":"researchers-uncover-aeternum-c2-infrastructure-with-advanced-persistence-and-network-evasion-features","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/28\/researchers-uncover-aeternum-c2-infrastructure-with-advanced-persistence-and-network-evasion-features\/","title":{"rendered":"Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features"},"content":{"rendered":"<p>    Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>For years, taking down a botnet meant finding its command-and-control (C2) server, seizing the domain, and watching the network go dark. Law enforcement used this method to dismantle major operations like Emotet, TrickBot, and QakBot. <\/p>\n<p>A newly discovered botnet loader called Aeternum C2 has been built specifically to close that door, storing all of its instructions not on any server or domain, but directly on the Polygon blockchain.<\/p>\n<p>Aeternum\u2019s commands live inside smart contracts on the Polygon network, a public blockchain replicated across thousands of nodes worldwide. <\/p>\n<p>Since there is no single server to seize or domain to suspend, the infrastructure remains available regardless of what any authority or platform chooses to do. <\/p>\n<p>Defenders who have spent years dismantling botnets through infrastructure seizure now face a model where that strategy simply does not work, and Aeternum appears to be the first commercially available implementation to make blockchain-based C2 a ready-to-use product.<\/p>\n<p><a href=\"https:\/\/qrator.net\/blog\/details\/Exploring-Aeternum-C2\/\" id=\"https:\/\/qrator.net\/blog\/details\/Exploring-Aeternum-C2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Qrator Labs analysts identified the loader<\/a> while monitoring cybercrime networks, noting it is written in native C++ and available in both 32-bit and 64-bit builds. <\/p>\n<p>Researchers found that every command issued to infected machines is recorded as a transaction on the Polygon blockchain, with bots reading those commands through public remote procedure call (RPC) endpoints. <\/p>\n<p>According to the seller\u2019s documentation, all active bots receive updates within two to three minutes \u2014 faster and more consistent than traditional peer-to-peer botnets.<\/p>\n<p>The botnet is marketed on underground forums as either a lifetime license with a preconfigured build or as full C++ source code with ongoing updates. <\/p>\n<p>Running costs are negligible: just $1 worth of MATIC, Polygon\u2019s native token, covers 100 to 150 command transactions. <\/p>\n<p>With no servers to rent or domains to register, the operational overhead for maintaining a resilient botnet is close to zero, placing it within reach of far more threat actors.<\/p>\n<p>The potential damage from botnets built on this model stretches well beyond individual campaigns. <\/p>\n<p>Once deployed, they can grow uninterrupted and be used for large-scale <a href=\"https:\/\/cybersecuritynews.com\/ddos-attacks-mitigation-strategies\/\" id=\"108208\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS attacks<\/a>, credential stuffing, click fraud, proxy-as-a-service abuse, and data theft. <\/p>\n<p>Even a complete cleanup of infected machines leaves the operator\u2019s smart contracts intact, meaning a full redeployment is possible at any moment without rebuilding infrastructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"blockchain-based-c2-how-aeternum-operates-and-evad\">Blockchain-Based C2: How Aeternum Operates and Evades Detection<\/h2>\n<p>The operator manages everything through a web-based control panel. From this interface, the attacker selects a smart contract, picks a command type \u2014 whether targeting all bots, pinging a specific machine by hardware ID (HWID), or pushing a <a href=\"https:\/\/cybersecuritynews.com\/blackwood-apt-escalate-privileges\/\" id=\"55449\" target=\"_blank\" rel=\"noreferrer noopener\">DLL loader<\/a> \u2014 then provides a payload URL and publishes the update to the blockchain.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgF765vejse0FDeIE29KW2maY9ssM0XD-HgnVV6iCuRtLhj61Fn0KDUTPG260M5EA3jAB5gtLNVTYdxe-lINH0a6IJP4D6jeb-jBoM7riyfBKHRYxCMRLSGWfRg5YkQF1-bAgRwYvHWPPfLphyphenhyphenLHPpKvKAVeI4VEY5scW9WIKF0P50ZVM4Ijzz7PHHaLL4\/s16000\/The%2520Aeternum%2520C2%2520Dashboard%2520%28Source%2520-%2520Qrator%2520Labs%29.webp?ssl=1\" alt=\"The Aeternum C2 Dashboard (Source - Qrator Labs)\"><figcaption class=\"wp-element-caption\">The Aeternum C2 Dashboard (Source \u2013 Qrator Labs)<\/figcaption><\/figure>\n<\/div>\n<p>Once confirmed on-chain, a command cannot be altered or removed by anyone except the wallet owner. The operator can run multiple contracts at once, with each one tied to a different function such as a clipper, a stealer, a remote access tool (RAT), or a miner.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9hsecTQRU_ceHrKvWYauWIqJStzpO2Z6K8mV_-LLkUDFlc75wrthyphenhyphenbnbLtKfU8LziJUj3irbb4W0VF3q46gCCmDnHr1cr6pMGn2OsRExU4wnH8fH94-LvKnBDggUk_1krp3-Adn8LGbSjxff2pi0oP5hwbsjSQaSF_e7tvr7ZInK70mGJLmr7V_HbtOA\/s16000\/Contract%2520Management%2520Panel%2520Showing%252013%2520Active%2520Smart%2520Contracts%2520%28Source%2520-%2520Qrator%2520Labs%29.webp?ssl=1\" alt=\"Contract Management Panel Showing 13 Active Smart Contracts (Source - Qrator Labs)\"><figcaption class=\"wp-element-caption\">Contract Management Panel Showing 13 Active Smart Contracts (Source \u2013 Qrator Labs)<\/figcaption><\/figure>\n<\/div>\n<p>Aeternum also includes <a href=\"https:\/\/cybersecuritynews.com\/new-mintsloader-employs-domain-generation-algorithm-anti-vm-techniques\/\" id=\"89129\" target=\"_blank\" rel=\"noreferrer noopener\">anti-VM detection<\/a>, blocking execution inside virtualized environments typically used by antivirus vendors and malware analysts. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh1dGG31BHbVsHhSIUFzZso5GBkafxjSFaKK96EAZQn_p3o_A-lSWgt0fuWSpKAREaXgnUOG8WtAvhUP8ypG3aqG4MiT_6VQHdgD-HHK8Iz8LozKQ6-qURPesUa5pfX1VvgiUw6dHv2xu_6_kWxYRYpex4Q8UXLUs1pbD1ZuD7v93P_YOxVxeDw2NJ9y0M\/s16000\/Built-in%2520AV%2520Scanner%2520Showing%2520Detection%2520Rates%2520Across%252037%2520Engines%2520%28Source%2520-%2520Qrator%2520Labs%29.webp?ssl=1\" alt=\"Built-in AV Scanner Showing Detection Rates Across 37 Engines (Source - Qrator Labs)\"><figcaption class=\"wp-element-caption\">Built-in AV Scanner Showing Detection Rates Across 37 Engines (Source \u2013 Qrator Labs)<\/figcaption><\/figure>\n<\/div>\n<p>The seller bundles a scantime scanner powered by the Kleenscan API.\u00a0This\u00a0shows that only 12 of 37 engines flagged the sample, while CrowdStrike, Avast, Avira, and ClamAV all returned clean results at the time of testing.<\/p>\n<p id=\"recommendations\">Traditional domain seizures and server takedowns will not stop a blockchain-based C2 channel. Security teams should focus on endpoint detection, behavioral monitoring, and strict application controls to catch suspicious executables early. <\/p>\n<p id=\"recommendations\"><a href=\"https:\/\/cybersecuritynews.com\/nsa-release-guidance-bulletproof-hosting\/\" id=\"133871\" target=\"_blank\" rel=\"noreferrer noopener\">Network defenders<\/a> should evaluate whether outbound connections to known Polygon RPC endpoints can be monitored or restricted without disrupting legitimate operations. <\/p>\n<p id=\"recommendations\">Since infrastructure-level takedowns are no longer reliable against this model, proactive traffic filtering at the network edge remains the most dependable line of defense.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-aeternum-c2-infrastructure\/\">Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-aeternum-c2-infrastructure\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features For years, taking down a botnet meant finding its command-and-control (C2) server, seizing the domain, and watching the network go dark. Law enforcement used this method to dismantle major operations like Emotet, TrickBot, and QakBot. A newly discovered botnet loader called Aeternum C2 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11015","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11015"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11015"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11015\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}