Threat reportMalwareTL-2026-1979
Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig
Aeternum Loader Uses Polygon Blockchain Smart Contracts for (TL-2026-1979), also tracked as Aeternum C2, is a high-severity malware campaign, first published 2026-08-10 and last reviewed 2026-08-17. It is attributed to LenAI with medium confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 39 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 1LenAI
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 39Indicators of compromise
Key facts for TL-2026-1979
- Threat ID
- TL-2026-1979
- Also known as
- Aeternum C2, Aeternum Botnet
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- LenAI
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 39
- Updates
- 2026-08-17 · revalidated 1× · latest source
Malware and tooling in Aeternum Loader Uses Polygon Blockchain Smart Contracts for
Malware and tooling: Aeternum, XWorm, xmrig, 0x04E25a563f159308FC3E15fE9Ccc9D2CF623D0cc, 0x75cD25791A60ab3451E2d2feB5ec46c6f541C2B8, 0xb0874252a7359AA701F3F144A1f03A6e0DA8aE6D, 0xcaf2c54e400437da717cf215181b170f65187abf, api.telegram.org
How Aeternum Loader Uses Polygon Blockchain Smart Contracts for works
Unit 42 documents Aeternum, a Windows botnet loader (C++ PE and PyInstaller-packed Python 3.14 variants) that reads encrypted commands from Polygon blockchain smart contracts via public JSON-RPC endpoints, eliminating any seizable/sinkholeable server or domain. The loader has delivered XWorm RAT, XMRig cryptominer, and a Telegram-based data-exfiltration module; Advanced Threat Prevention recorded 29,000+ detection events as of June 4, 2026, and the toolkit is attributed to underground-forum actor "LenAI" (also behind the ErrTraffic ClickFix toolkit).
Aeternum is a native C++ (32-bit, UPX-packed) botnet loader with a parallel PyInstaller-packed Python 3.14 variant that impersonates a DBeaver installer. Both variants use the Polygon blockchain as their sole command-and-control channel: infected hosts issue eth_call JSON-RPC requests (function selectors 0xb68d1809 getDomain, 0xb249cd2d updateDomain, 0xf851a440 admin) against operator-controlled smart contracts through public Polygon RPC endpoints, retrieving a 266-byte encrypted payload that is decrypted client-side with PBKDF2HMAC-SHA256 + AES-GCM. Because the password is reused as its own salt (a NIST SP 800-132-flagged predictable-salt weakness), any analyst holding the contract address and payload can recover the plaintext command without the operator's key. Unit 42 observed 22+ distinct smart contract addresses across sampled builds and documented active use of updateDomain() to rotate C2 without redeploying code.
Three case samples were analyzed: a standalone C++ loader (Build.exe), a trojanized-DBeaver Python variant with sandbox/anti-analysis gating (8GB RAM minimum, sandbox-username blocklist, Zone.Identifier ADS check, VM/AV detection), and a composite 64-bit PyInstaller binary (XBinderOutput_protected.exe) that bundles XWorm RAT, XMRig, and a .NET data-exfiltration module (DotNetZip.dll) behind Early Bird APC injection into the signed Windows binary dpapimig.exe. Post-compromise, the loader fetches supporting tools (a legitimate PuTTY binary, DotNetZip.dll) from GitHub repositories, establishes Startup-folder persistence via a .lnk shortcut, and deploys payloads: XWorm v7.4 for interactive remote access, XMRig (configured via a Pastebin raw paste) mining Monero to a MoneroOcean pool, and a Telegram Bot API exfiltration channel that ships host fingerprinting data (CPU/RAM/disk/GPU, UAC/admin status) and a desktop screenshot. A separate composite sample exfiltrates to a dedicated HTTP C2 (193.221.200.219) using AES-128-ECB with zero-padding.
Attribution centers on a blockchain wallet (0xcaf2c54e400437da717cf215181b170f65187abf) tied to the underground-forum moniker "LenAI," who first advertised Aeternum in December 2025 (per Outpost24 KrakenLabs) at $200 for a configured panel/build or $4,000 for the full C++ codebase, and by March 2026 was seeking $10,000 to exit-sell the toolkit entirely. LenAI is independently attributed to ErrTraffic, a $800 ClickFix delivery-automation toolkit (Lumma/Vidar/AMOS/Cerberus payloads) that geofences out CIS countries -- a common Russian-speaking-actor OPSEC pattern -- and which LenAI rebuilt in February 2026 to also use Polygon smart contracts for its own C2 rotation, indicating the blockchain-C2 technique is being productized across LenAI's toolset rather than confined to Aeternum. Unit 42's research builds on prior Qrator Labs and Ctrl-Alt-Intel analysis of the loader and C2 architecture, and notes a possible but unconfirmed behavioral overlap with Cisco Talos's 2022 ZingoStealer in one sample.
MITRE ATT&CK techniques used in TL-2026-1979
Collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1568 Dynamic Resolution; T1573 Encrypted Channel
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading; T1055 Process Injection; T1055.004 Process Injection; T1112 Modify Registry; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1119 Automated Exfiltration; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
Discovery
T1082 System Information Discovery
Initial Access
Impact
Persistence
T1547 Boot or Logon Autostart Execution; T1547.001 Boot or Logon Autostart Execution; T1547.009 Boot or Logon Autostart Execution; T1574.002 Hijack Execution Flow
Resource Development
defense-impairment
Affected products and versions in Aeternum Loader Uses Polygon Blockchain Smart Contracts for
- Microsoft — Windows
Vulnerable versions: All supported Windows versions (x32/x64), no OS vulnerability -- malware runs as a user-executed binary
Remediation for Aeternum Loader Uses Polygon Blockchain Smart Contracts for
Immediate actions
- Block/alert on outbound JSON-RPC (eth_call) traffic to public Polygon RPC endpoints from endpoints that have no legitimate blockchain-development use case
- Block network indicators: 193.221.200.219, sekirolegion.duckdns.org, cdnjsdelivr.beer, gulf.moneroocean.stream
- Hunt for and remove the Startup-folder .lnk persistence pattern Wmi_Framework_APIKEY_wmsnet_<random>.lnk
- Flag process injection into dpapimig.exe or other signed system binaries via Early Bird APC as high-confidence malicious
- Deploy/verify Palo Alto Threat Prevention signatures 87116 and 87152; enable Advanced WildFire and Advanced URL Filtering/DNS Security
Workarounds
- Restrict outbound access to public blockchain RPC provider domains at the network egress for endpoints with no business justification
Longer-term hardening
- Deploy EDR/XDR behavioral detection for blockchain-RPC-based C2 patterns (Cortex XDR Behavioral Threat Protection or equivalent), since this class of C2 has no static domain/IP to blocklist long-term
- Monitor for unsigned/unexpected PyInstaller-packed binaries and UPX-packed PE loaders in user-writable paths
- Educate developer/DBA populations on trojanized installer risk given the DBeaver-impersonation lure
- Track LenAI/ErrTraffic-linked infrastructure and TTP evolution given the actor's active toolkit development
Weaknesses (CWE) in Aeternum Loader Uses Polygon Blockchain Smart Contracts for
Timeline of Aeternum Loader Uses Polygon Blockchain Smart Contracts for
- Cisco Talos publishes ZingoStealer attribution research; Unit 42 later notes a possible but unconfirmed behavioral overlap with one Aeternum composite sample.
- Malicious DotNetZip.dll committed to an attacker-controlled GitHub repository, later served alongside a legitimate PuTTY binary for DLL side-loading by Aeternum Sample 1.
- Threat actor LenAI begins advertising the Aeternum botnet on underground forums ($200 for a configured panel/build, $4,000 for the full C++ codebase); Outpost24 KrakenLabs issues initial disclosure.
- LenAI's separate ErrTraffic ClickFix delivery toolkit is rebuilt (v3) to also use Polygon smart contracts for its own C2 rotation, indicating the blockchain-C2 technique is being productized across LenAI's tool line.
- Qrator Labs' research on Aeternum's blockchain-based C2 architecture is publicly reported (The Hacker News), detailing the Polygon smart-contract command channel and LenAI's pricing model.
- LenAI expands ErrTraffic with macOS ClickFix support and is reported seeking $10,000 to sell the complete Aeternum toolkit outright.
- XMRig cryptomining configuration data (MoneroOcean pool, payout wallet) observed in Aeternum Sample 2 telemetry.
- Palo Alto Networks Advanced Threat Prevention has logged 29,000+ Aeternum-related detection events.
- Unit 42 publishes a comprehensive Aeternum report covering three malware case samples, the getDomain/updateDomain/admin smart-contract C2 protocol, the predictable-salt cryptographic weakness, and delivered XWorm/XMRig/exfiltration payloads.
- Cyber Security News and other outlets (Security Affairs, GBHackers, Infosecurity Magazine) republish and summarize the Unit 42 findings, bringing wider public attention to the campaign.
Update history for TL-2026-1979
- 2026-08-17 — Aeternum Botnet Loader Abuses Polygon Blockchain Smart Contracts for Takedown-Resistant C2: What changed No escalation to severity_level (HIGH), exploitability (ACTIVE), or status (ACTIVE). Newer coverage adds a previously undocumented cryptocurrency-infostealer component (55+ browser wallet extensions, 10 desktop wallet apps targ
Sources cited for Aeternum Loader Uses Polygon Blockchain Smart Contracts for
- Aeternum: Blockchain-Based C2 Analysis
- Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
- Aeternum C2 botnet leverages blockchain for resilient command and control
- New Aeternum C2 Botnet Evades Takedowns via Polygon Blockchain
- Aeternum Botnet Shifts Command Control to Polygon Blockchain
- Aeternum botnet hides commands in Polygon smart contracts
- Aeternum C2 Botnet Abuses Polygon Blockchain to Hide Malware Commands and Evade Takedowns
- Aeternum C2: The Botnet That Lives on the Polygon Blockchain
- New ErrTraffic service enables ClickFix attacks via fake browser glitches
- ZingoStealer attribution research
- NIST SP 800-132: Recommendation for Password-Based Key Derivation
Detection coverage for TL-2026-1979
As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1979 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1979
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.