Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown

2026-03-05T14:21:05Z43da0ddf3f8419eb455b38e55a8bab8c02b617a3e69ef0f1a25544bc330de7b2
DohdoorUAT-10027aeternumanthropicapi-key-exfiltrationbackdoorblockchain-c2botnetcisco-sd-wanclaudedeveloper-targetingdns-over-httpsdohfilezenin-memory-malwarelazarusmedusa-ransomwarenextjsnpmnugetpolygonrcesolarwinds-serv-ustripeapisupply-chain

What happened

The collection highlights multiple high-impact active threats and supply-chain attacks: a novel Aeternum C2 botnet stores encrypted commands on the public Polygon blockchain to resist takedown; Cisco Catalyst SD‑WAN has a max‑severity zero-day (CVE-2026-20127) exploited since 2023 for unauthenticated admin access; CISA confirmed active exploitation of FileZen OS command injection (CVE-2026-25108). Researchers also disclosed widespread developer- and package-targeting campaigns (malicious NuGet/StripeApi packages, fake Next.js repos delivering in-memory malware), critical SolarWinds Serv-U 15.5

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
43da0ddf3f8419eb455b38e55a8bab8c02b617a3e69ef0f1a25544bc330de7b2
Enrichment time
2026-03-05T14:21:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.