Threat reportMalwareTL-2026-0151

Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS

criticalACTIVE

Aeternum C2 Botnet (TL-2026-0151) is a critical-severity malware campaign, first published 2026-02-27. It is attributed to LenAI, maps to 20 MITRE ATT&CK techniques (T1027, T1036.005, T1055.001), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
1LenAI
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0151

Threat ID
TL-2026-0151
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
LenAI
Detection rules
9
Indicators of compromise
20

Malware and tooling in Aeternum C2 Botnet

Malware and tooling: Aeternum C2

How Aeternum C2 Botnet works

Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.

Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.

MITRE ATT&CK techniques used in TL-2026-0151

defense-evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Dynamic-link Library Injection; T1070.004 File Deletion; T1134.004 Parent PID Spoofing; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.004 NTFS File Attributes

execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File

command-and-control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

discovery

T1082 System Information Discovery

persistence

T1547.001 Registry Run Keys / Startup Folder

defense-impairment

T1553.005 Mark-of-the-Web Bypass

resource-development

T1583.005 Botnet

Timeline of Aeternum C2 Botnet

  • Earliest decrypted Aeternum C2 command on Polygon blockchain, indicating operational deployment since at least October 2025
  • KrakenLabs (Outpost24) first discloses Aeternum C2 loader advertised by LenAI on underground forums — $200 panel, $4,000 source
  • Second most active Polygon wallet (0x6e3c...e49b) deploys 22 smart contracts in under 3 minutes, sends commands using unknown encryption scheme
  • LenAI's Polygon wallet begins creating smart contracts for ErrTraffic/ClickFix campaigns using same bytecode — operational link confirmed
  • Latest decrypted C2 command in Ctrl Alt Intel analysis (209 total commands across 37 decryptable channels)
  • Polygonscan reveals 400 addresses hosting identical Aeternum smart contract bytecode on Polygon mainnet
  • LenAI posts full project sale for $10,000 on underground forum, citing lack of time for support. Source: KrakenLabs
  • Ctrl Alt Intel publishes two-part deep analysis: Part 1 (panel, blockchain, decryption) and Part 2 (binary reversing, anti-VM, loader features)
  • Qrator Labs and The Hacker News publish reports. Threadlinqs Intelligence publishes TL-2026-0151 with full MITRE mapping and detections
  • As of 2026-05-29, Aeternum C2 (LenAI MaaS) remains ACTIVE: its ~400 immutable Polygon smart-contract C2s are takedown-resistant by design, with no arrest, seizure, or law-enforcement disruption reported (The Hacker News, Qrator Labs, Outpost24/KrakenLabs). No CVE exists to patch, the loader is still sold as MaaS, and no successor supersedes it.

Sources cited for Aeternum C2 Botnet

Detection coverage for TL-2026-0151

As of 2026-02-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0151 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats