LenAI
❔ UnknownLast active: 2026-08-11First seen: 2026-08-11
0
linked CVEs
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Source: otx · Collected: 2026-08-11
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs40
| sha1 | d3e0f9448c94b1017f26e4da63b710a886a2b426 | — | 2026-08-11 |
| domain | polygon-zkevm.drpc.org | — | 2026-08-11 |
| sha1 | 326a4305420a5c57950a7ee8c1e41b31132dd027 | — | 2026-08-11 |
| domain | rpc.poolz.finance | — | 2026-08-11 |
| domain | polygon-mumbai.gateway.tenderly.co | — | 2026-08-11 |
| sha256 | 1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505 | — | 2026-08-11 |
| md5 | 66575cc1df33e40a47fe00abdc067fe5 | — | 2026-08-11 |
| sha256 | 5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898 | — | 2026-08-11 |
| sha1 | b51a50ffc57565c8488cb8101252db0e60619750 | — | 2026-08-11 |
| md5 | 1ef50e9d715245e29220936a66c0bece | — | 2026-08-11 |
| domain | api.zan.top | — | 2026-08-11 |
| sha256 | ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2 | — | 2026-08-11 |
| sha256 | f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27 | — | 2026-08-11 |
| domain | polygon-amoy.therpc.io | — | 2026-08-11 |
| domain | download.sftp-api-group-wechat.com | — | 2026-08-11 |
| sha256 | 4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f | — | 2026-08-11 |
| domain | polygon-zkevm-mainnet.public.blastapi.io | — | 2026-08-11 |
| domain | sekirolegion.duckdns.org | — | 2026-08-11 |
| md5 | 848b1440f5f52bfddf2e1b3e9e248f12 | — | 2026-08-11 |
| md5 | 673a51a179a78fbdf2b8770f868f883a | — | 2026-08-11 |
| md5 | a45e8679d2695d10a45a3f78268fab64 | — | 2026-08-11 |
| sha1 | d224dde23da2faff57235192333fc7998762c645 | — | 2026-08-11 |
| domain | polygon.rpc.hypersync.xyz | — | 2026-08-11 |
| domain | update.constant-path.xyz | — | 2026-08-11 |
| domain | rpc.polygon-zkevm.gateway.fm | — | 2026-08-11 |
| domain | polygontestapi.terminet.io | — | 2026-08-11 |
| domain | polygon-amoy.gateway.tenderly.co | — | 2026-08-11 |
| domain | polygon-mumbai-bor-rpc.publicnode.com | — | 2026-08-11 |
| domain | endpoints.omniatech.io | — | 2026-08-11 |
| ip | 193.221.200.219 | — | 2026-08-11 |
| domain | rpc.polygonsupernet.public.arianee.net | — | 2026-08-11 |
| domain | cdnjsdelivr.beer | — | 2026-08-11 |
| sha1 | 96f6794fa4b7414e38be4ef497cd8611d50a59ec | — | 2026-08-11 |
| domain | update-launcher.xyz | — | 2026-08-11 |
| sha256 | 81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f | — | 2026-08-11 |
| sha1 | cfd101963a4e791fc59bda97bfc87f33ce7ce379 | — | 2026-08-11 |
| url | https://rpc.polygon-zkevm.gateway.fm | — | 2026-08-11 |
| domain | api.noderpc.xyz | — | 2026-08-11 |
| domain | test-steve.cyou | — | 2026-08-11 |
| md5 | cd8b231a2101c7de3f0b118f99279cbd | — | 2026-08-11 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.