# Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig

> Unit 42 documents Aeternum, a Windows botnet loader (C++ PE and PyInstaller-packed Python 3.14 variants) that reads encrypted commands from Polygon blockchain smart contracts via public JSON-RPC endpoints, eliminating any seizable/sinkholeable server or domain. The loader has delivered XWorm RAT, XMRig cryptominer, and a Telegram-based data-exfiltration module; Advanced Threat Prevention recorded 29,000+ detection events as of June 4, 2026, and the toolkit is attributed to underground-forum actor "LenAI" (also behind the ErrTraffic ClickFix toolkit).

- **Published:** 2026-08-10T00:00:00Z
- **Last reviewed:** 2026-08-17T04:18:13.502Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1979
- **ID:** TL-2026-1979
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** LenAI
- **Detections:** 9 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Aeternum is a native C++ (32-bit, UPX-packed) botnet loader with a parallel PyInstaller-packed Python 3.14 variant that impersonates a DBeaver installer. Both variants use the Polygon blockchain as their sole command-and-control channel: infected hosts issue eth_call JSON-RPC requests (function selectors 0xb68d1809 getDomain, 0xb249cd2d updateDomain, 0xf851a440 admin) against operator-controlled smart contracts through public Polygon RPC endpoints, retrieving a 266-byte encrypted payload that is decrypted client-side with PBKDF2HMAC-SHA256 + AES-GCM. Because the password is reused as its own salt (a NIST SP 800-132-flagged predictable-salt weakness), any analyst holding the contract address and payload can recover the plaintext command without the operator's key. Unit 42 observed 22+ distinct smart contract addresses across sampled builds and documented active use of updateDomain() to rotate C2 without redeploying code.

Three case samples were analyzed: a standalone C++ loader (Build.exe), a trojanized-DBeaver Python variant with sandbox/anti-analysis gating (8GB RAM minimum, sandbox-username blocklist, Zone.Identifier ADS check, VM/AV detection), and a composite 64-bit PyInstaller binary (XBinderOutput_protected.exe) that bundles XWorm RAT, XMRig, and a .NET data-exfiltration module (DotNetZip.dll) behind Early Bird APC injection into the signed Windows binary dpapimig.exe. Post-compromise, the loader fetches supporting tools (a legitimate PuTTY binary, DotNetZip.dll) from GitHub repositories, establishes Startup-folder persistence via a .lnk shortcut, and deploys payloads: XWorm v7.4 for interactive remote access, XMRig (configured via a Pastebin raw paste) mining Monero to a MoneroOcean pool, and a Telegram Bot API exfiltration channel that ships host fingerprinting data (CPU/RAM/disk/GPU, UAC/admin status) and a desktop screenshot. A separate composite sample exfiltrates to a dedicated HTTP C2 (193.221.200.219) using AES-128-ECB with zero-padding.

Attribution centers on a blockchain wallet (0xcaf2c54e400437da717cf215181b170f65187abf) tied to the underground-forum moniker "LenAI," who first advertised Aeternum in December 2025 (per Outpost24 KrakenLabs) at $200 for a configured panel/build or $4,000 for the full C++ codebase, and by March 2026 was seeking $10,000 to exit-sell the toolkit entirely. LenAI is independently attributed to ErrTraffic, a $800 ClickFix delivery-automation toolkit (Lumma/Vidar/AMOS/Cerberus payloads) that geofences out CIS countries -- a common Russian-speaking-actor OPSEC pattern -- and which LenAI rebuilt in February 2026 to also use Polygon smart contracts for its own C2 rotation, indicating the blockchain-C2 technique is being productized across LenAI's toolset rather than confined to Aeternum. Unit 42's research builds on prior Qrator Labs and Ctrl-Alt-Intel analysis of the loader and C2 architecture, and notes a possible but unconfirmed behavioral overlap with Cisco Talos's 2022 ZingoStealer in one sample.

## MITRE ATT&CK

- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1497 Virtualization/Sandbox Evasion
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1113 Screen Capture
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1568 Dynamic Resolution
- T1567 Exfiltration Over Web Service
- T1496 Resource Hijacking
- T1588 Obtain Capabilities
- T1204.002 User Execution
- T1036.005 Masquerading
- T1574.002 Hijack Execution Flow
- T1055.004 Process Injection
- T1547.001 Boot or Logon Autostart Execution
- T1547.009 Boot or Logon Autostart Execution
- T1106 Native API
- T1112 Modify Registry
- T1622 Debugger Evasion
- T1071.001 Application Layer Protocol
- T1008 Fallback Channels
- T1041 Exfiltration Over C2 Channel
- T1119 Automated Exfiltration
- T1115 Clipboard Data
- T1005 Data from Local System
- T1056 Input Capture

## Sources

- [Aeternum: Blockchain-Based C2 Analysis](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)
- [Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown](https://thehackernews.com/2026/02/aeternum-c2-botnet-stores-encrypted.html)
- [Aeternum C2 botnet leverages blockchain for resilient command and control](https://www.scworld.com/brief/aeternum-c2-botnet-leverages-blockchain-for-resilient-command-and-control)
- [New Aeternum C2 Botnet Evades Takedowns via Polygon Blockchain](https://hackread.com/aeternum-c2-botnet-polygon-blockchain/)
- [Aeternum Botnet Shifts Command Control to Polygon Blockchain](https://www.infosecurity-magazine.com/news/aeternum-botnet-c2-polygon/)
- [Aeternum botnet hides commands in Polygon smart contracts](https://securityaffairs.com/188627/mobile-2/aeternum-botnet-hides-commands-in-polygon-smart-contracts.html)
- [Aeternum C2 Botnet Abuses Polygon Blockchain to Hide Malware Commands and Evade Takedowns](https://cyberwarzone.com/2026/03/08/aeternum-c2-botnet-abuses-polygon-blockchain-to-hide-malware-commands-and-evade-takedowns/)
- [Aeternum C2: The Botnet That Lives on the Polygon Blockchain](https://dev.to/deepseax/aeternum-c2-the-botnet-that-lives-on-the-polygon-blockchain-c3g)
- [New ErrTraffic service enables ClickFix attacks via fake browser glitches](https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/)
- [ZingoStealer attribution research](https://blog.talosintelligence.com/)
- [NIST SP 800-132: Recommendation for Password-Based Key Derivation](https://csrc.nist.gov/publications/detail/sp/800-132/final)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1979
