$ techbeacon
Darkweb

Unstoppable Commands: How Aeternum Malware Uses the Polygon Blockchain to Evade Security Takedowns

Unstoppable Commands: How Aeternum Malware Uses the Polygon Blockchain to Evade Security Takedowns

Cybersecurity researchers have uncovered a sophisticated malware campaign dubbed "Aeternum" that utilizes the public Polygon blockchain to host its command-and-control infrastructure. By embedding malicious instructions directly into the decentralized ledger, the operators of the malware have found a way to coordinate botnet activities without relying on traditional, vulnerable web servers.

In a typical cyberattack, threat actors communicate with infected devices using command-and-control (C2) servers. When security agencies or hosting providers detect these servers, they can shut down the associated domains or physically seize the hardware, effectively neutralizing the threat. Aeternum, however, bypasses this vulnerability entirely by writing its commands directly into Polygon transactions, ensuring that the instructions remain permanently accessible to infected hosts.

The choice of the Polygon blockchain is highly strategic. As a prominent scaling solution, Polygon offers rapid transaction speeds and extremely low fees, allowing the malware operators to update their instructions frequently and cost-effectively. Because blockchain technology relies on a distributed ledger where data is immutable, no single authority or security firm has the power to delete or alter the malware's instructions once they are published.

This architectural shift presents a formidable challenge to modern cybersecurity defenses. Traditional incident response relies heavily on "takedowns"—coordinating with internet service providers and domain registrars to block malicious traffic. With Aeternum, there is no central server to target. To disrupt the botnet, defenders must find alternative methods, such as blocking access to the blockchain gateways themselves, which could inadvertently impact legitimate decentralized applications.

While experimental uses of decentralized networks by cybercriminals have been observed in the past, Aeternum represents a highly practical and resilient implementation of this technique. As the boundaries of decentralized technology expand, security analysts warn that the industry must evolve. Future defense mechanisms will likely need to focus on detecting the initial malware infections on endpoint devices or analyzing blockchain transactions in real-time to flag anomalous interactions before they can trigger widespread harm.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related