Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
2026-03-05T13:47:45Z•c3badb8d2d3272570ce5303bf32a381ea16dc6bcea6f7996c494a2785315c9ce
CVE-2025-40538CVE-2025-49113CVE-2026-20127CVE-2026-25108API-token-theftAeternumCisco-SD-WANDNS-over-HTTPSDohdoorFileZenNuGetPolygonRCERoundcubeSolarWinds-Serv-UUAT-10027blockchain-C2credential-exfiltrationcryptojacking-XMRigdeveloper-targetingin-memory-malwarenpmpackage-impersonationsupply-chainzero-day
What happened
The collection highlights a surge of high-impact and diverse threats: Aeternum C2 uses the public Polygon blockchain to store encrypted botnet commands; UAT-10027 is delivering a new Dohdoor backdoor using DNS-over-HTTPS; multiple supply-chain and developer-targeting campaigns (malicious NuGet/npm packages, a StripeApi.Net impersonation, and fake Next.js repos) are stealing API tokens, credentials, and seeding in-memory malware; critical/actively exploited vulnerabilities include a Cisco SD‑WAN zero-day (CVE-2026-20127) exploited since 2023 and a FileZen OS command injection (CVE-2026-25108) (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c3badb8d2d3272570ce5303bf32a381ea16dc6bcea6f7996c494a2785315c9ce
- Enrichment time
- 2026-03-05T13:47:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.