Aeternum Malware Loader Uses Polygon Blockchain for Resilient Command Infrastructure
A new malware loader called Aeternum is using the Polygon blockchain to establish a command-and-control mechanism that's resistant to conventional takedown efforts.
Researchers at Unit 42 discovered that the malware stores operational instructions in a Polygon smart contract, allowing infected systems to retrieve information from a publicly replicated blockchain network.
The campaign has been linked to several malware samples that share code characteristics and smart-contract functions. Investigators identified a packed loader, an XWorm and XMRig package, and Python-based malware disguised as a DBeaver software installer.
The findings indicate that the infrastructure can support multiple malicious activities, including remote access, information theft, cryptocurrency mining, and additional malware delivery.