SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

LenAI

❔ UnknownLast active: 2026-08-11First seen: 2026-08-11
0
linked CVEs
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Source: otx · Collected: 2026-08-11
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs40
sha1d3e0f9448c94b1017f26e4da63b710a886a2b4262026-08-11
domainpolygon-zkevm.drpc.org2026-08-11
sha1326a4305420a5c57950a7ee8c1e41b31132dd0272026-08-11
domainrpc.poolz.finance2026-08-11
domainpolygon-mumbai.gateway.tenderly.co2026-08-11
sha2561505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce5052026-08-11
md566575cc1df33e40a47fe00abdc067fe52026-08-11
sha2565bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d8468982026-08-11
sha1b51a50ffc57565c8488cb8101252db0e606197502026-08-11
md51ef50e9d715245e29220936a66c0bece2026-08-11
domainapi.zan.top2026-08-11
sha256ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a22026-08-11
sha256f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a272026-08-11
domainpolygon-amoy.therpc.io2026-08-11
domaindownload.sftp-api-group-wechat.com2026-08-11
sha2564e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f2026-08-11
domainpolygon-zkevm-mainnet.public.blastapi.io2026-08-11
domainsekirolegion.duckdns.org2026-08-11
md5848b1440f5f52bfddf2e1b3e9e248f122026-08-11
md5673a51a179a78fbdf2b8770f868f883a2026-08-11
md5a45e8679d2695d10a45a3f78268fab642026-08-11
sha1d224dde23da2faff57235192333fc7998762c6452026-08-11
domainpolygon.rpc.hypersync.xyz2026-08-11
domainupdate.constant-path.xyz2026-08-11
domainrpc.polygon-zkevm.gateway.fm2026-08-11
domainpolygontestapi.terminet.io2026-08-11
domainpolygon-amoy.gateway.tenderly.co2026-08-11
domainpolygon-mumbai-bor-rpc.publicnode.com2026-08-11
domainendpoints.omniatech.io2026-08-11
ip193.221.200.2192026-08-11
domainrpc.polygonsupernet.public.arianee.net2026-08-11
domaincdnjsdelivr.beer2026-08-11
sha196f6794fa4b7414e38be4ef497cd8611d50a59ec2026-08-11
domainupdate-launcher.xyz2026-08-11
sha25681bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f2026-08-11
sha1cfd101963a4e791fc59bda97bfc87f33ce7ce3792026-08-11
urlhttps://rpc.polygon-zkevm.gateway.fm2026-08-11
domainapi.noderpc.xyz2026-08-11
domaintest-steve.cyou2026-08-11
md5cd8b231a2101c7de3f0b118f99279cbd2026-08-11
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.