New Aeternum C2 Botnet Evades Takedowns via Polygon Blockchain
2026-03-04T21:04:27Z•c854381f6d63a58c181135ef82d66639b201f99ca38cbe9137d6ae52a941f36b
Aeternum C2Avast fake siteBen.nlChatGPTEntra IDMFA bypassOAuth consentOdidoOperation ZeroPolygonShinyHuntersUS Treasury sanctionsVulnCheck report 1% rule','MTTR reduction','threat visibility','blockchain C2botnetdata breachemail accessexploit brokerpayment card fraudpersistent accessphishingrefund scamstolen government toolstakedown evasionvulnerability prioritization
What happened
Recent reporting highlights multiple high-impact threats and defensive trends: a new Aeternum C2 botnet leverages the Polygon blockchain to host command-and-control, complicating takedowns and attribution; OAuth consent in Entra ID can grant applications (e.g., ChatGPT integrations) access to user emails and persistent privileges that may bypass MFA; a targeted phishing campaign clones Avast’s site to steal payment card data via a €499 “refund” scam; ShinyHunters claims a 21M-record breach at Odido NL / Ben.nl; and the U.S. Treasury sanctioned an exploit broker (Operation Zero) for trading ex‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- c854381f6d63a58c181135ef82d66639b201f99ca38cbe9137d6ae52a941f36b
- Enrichment time
- 2026-03-04T21:04:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.