Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown

2026-03-05T13:47:45Zc3badb8d2d3272570ce5303bf32a381ea16dc6bcea6f7996c494a2785315c9ce
CVE-2025-40538CVE-2025-49113CVE-2026-20127CVE-2026-25108API-token-theftAeternumCisco-SD-WANDNS-over-HTTPSDohdoorFileZenNuGetPolygonRCERoundcubeSolarWinds-Serv-UUAT-10027blockchain-C2credential-exfiltrationcryptojacking-XMRigdeveloper-targetingin-memory-malwarenpmpackage-impersonationsupply-chainzero-day

What happened

The collection highlights a surge of high-impact and diverse threats: Aeternum C2 uses the public Polygon blockchain to store encrypted botnet commands; UAT-10027 is delivering a new Dohdoor backdoor using DNS-over-HTTPS; multiple supply-chain and developer-targeting campaigns (malicious NuGet/npm packages, a StripeApi.Net impersonation, and fake Next.js repos) are stealing API tokens, credentials, and seeding in-memory malware; critical/actively exploited vulnerabilities include a Cisco SD‑WAN zero-day (CVE-2026-20127) exploited since 2023 and a FileZen OS command injection (CVE-2026-25108) (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c3badb8d2d3272570ce5303bf32a381ea16dc6bcea6f7996c494a2785315c9ce
Enrichment time
2026-03-05T13:47:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.