Threat reportMalwareTL-2026-0151
Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS
Aeternum C2 Botnet (TL-2026-0151) is a critical-severity malware campaign, first published 2026-02-27. It is attributed to LenAI, maps to 20 MITRE ATT&CK techniques (T1027, T1036.005, T1055.001), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 1LenAI
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0151
- Threat ID
- TL-2026-0151
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- LenAI
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Aeternum C2 Botnet
Malware and tooling: Aeternum C2
How Aeternum C2 Botnet works
Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.
Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.
MITRE ATT&CK techniques used in TL-2026-0151
defense-evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Dynamic-link Library Injection; T1070.004 File Deletion; T1134.004 Parent PID Spoofing; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.004 NTFS File Attributes
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File
command-and-control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography
discovery
T1082 System Information Discovery
persistence
T1547.001 Registry Run Keys / Startup Folder
defense-impairment
T1553.005 Mark-of-the-Web Bypass
resource-development
Timeline of Aeternum C2 Botnet
- Earliest decrypted Aeternum C2 command on Polygon blockchain, indicating operational deployment since at least October 2025
- KrakenLabs (Outpost24) first discloses Aeternum C2 loader advertised by LenAI on underground forums — $200 panel, $4,000 source
- Second most active Polygon wallet (0x6e3c...e49b) deploys 22 smart contracts in under 3 minutes, sends commands using unknown encryption scheme
- LenAI's Polygon wallet begins creating smart contracts for ErrTraffic/ClickFix campaigns using same bytecode — operational link confirmed
- Latest decrypted C2 command in Ctrl Alt Intel analysis (209 total commands across 37 decryptable channels)
- Polygonscan reveals 400 addresses hosting identical Aeternum smart contract bytecode on Polygon mainnet
- LenAI posts full project sale for $10,000 on underground forum, citing lack of time for support. Source: KrakenLabs
- Ctrl Alt Intel publishes two-part deep analysis: Part 1 (panel, blockchain, decryption) and Part 2 (binary reversing, anti-VM, loader features)
- Qrator Labs and The Hacker News publish reports. Threadlinqs Intelligence publishes TL-2026-0151 with full MITRE mapping and detections
- As of 2026-05-29, Aeternum C2 (LenAI MaaS) remains ACTIVE: its ~400 immutable Polygon smart-contract C2s are takedown-resistant by design, with no arrest, seizure, or law-enforcement disruption reported (The Hacker News, Qrator Labs, Outpost24/KrakenLabs). No CVE exists to patch, the loader is still sold as MaaS, and no successor supersedes it.
Sources cited for Aeternum C2 Botnet
Detection coverage for TL-2026-0151
As of 2026-02-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0151 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.