# Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS

> Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.

- **Published:** 2026-02-27T15:08:00Z
- **Last reviewed:** 2026-02-27T15:08:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0151
- **ID:** TL-2026-0151
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** LenAI
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Aeternum C2 is a native C++ botnet loader that uses Polygon blockchain smart contracts for command-and-control, making infrastructure permanently immune to takedowns. Sold as MaaS by threat actor LenAI.

## MITRE ATT&CK

- T1583.005 Botnet
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1204.002 Malicious File
- T1547.001 Registry Run Keys / Startup Folder
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1055.001 Dynamic-link Library Injection
- T1497.001 System Checks
- T1070.004 File Deletion
- T1553.005 Mark-of-the-Web Bypass
- T1134.004 Parent PID Spoofing
- T1564.004 NTFS File Attributes
- T1082 System Information Discovery
- T1102.002 Bidirectional Communication
- T1071.001 Web Protocols
- T1132.001 Standard Encoding
- T1573.001 Symmetric Cryptography
- T1105 Ingress Tool Transfer

## Sources

- [Aeternum Botnet C2 Analysis — Polygon Blockchain Smart Contract Infrastructure](https://github.com/aeternum-c2/analysis)
- [LenAI MaaS Marketplace Takedown Report](https://threatresearch.example.com/lenai-maas)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0151
