Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
2026-03-05T14:21:05Z•43da0ddf3f8419eb455b38e55a8bab8c02b617a3e69ef0f1a25544bc330de7b2
DohdoorUAT-10027aeternumanthropicapi-key-exfiltrationbackdoorblockchain-c2botnetcisco-sd-wanclaudedeveloper-targetingdns-over-httpsdohfilezenin-memory-malwarelazarusmedusa-ransomwarenextjsnpmnugetpolygonrcesolarwinds-serv-ustripeapisupply-chain
What happened
The collection highlights multiple high-impact active threats and supply-chain attacks: a novel Aeternum C2 botnet stores encrypted commands on the public Polygon blockchain to resist takedown; Cisco Catalyst SD‑WAN has a max‑severity zero-day (CVE-2026-20127) exploited since 2023 for unauthenticated admin access; CISA confirmed active exploitation of FileZen OS command injection (CVE-2026-25108). Researchers also disclosed widespread developer- and package-targeting campaigns (malicious NuGet/StripeApi packages, fake Next.js repos delivering in-memory malware), critical SolarWinds Serv-U 15.5
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 43da0ddf3f8419eb455b38e55a8bab8c02b617a3e69ef0f1a25544bc330de7b2
- Enrichment time
- 2026-03-05T14:21:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.