Cybersecurity Research

New 'Aeternum' Malware Uses Blockchain to Hide Its Command Centre

Unit 42 · 11 Aug 2026
Key Takeaway Keep software and security tools updated and monitor for unusual network activity, as attackers are increasingly using resilient, hard-to-block infrastructure like blockchain networks.

Researchers at Unit 42 have uncovered a new type of malware loader, dubbed Aeternum, that uses blockchain technology to control infected computers. Instead of relying on traditional servers to issue commands, Aeternum uses smart contracts on the Polygon blockchain to manage its communications and deliver malicious payloads.

This approach is significant because blockchain networks are decentralised and difficult to take down. Unlike a conventional command-and-control server, which security teams can often identify and block, a blockchain-based system can continue operating even if parts of the network are disrupted, giving attackers a more resilient and persistent foothold.

While this type of attack is technically sophisticated, it reflects a broader trend of cybercriminals adopting decentralised technologies to make their operations more resilient. Small businesses may not be direct targets of such advanced tools, but the malware could still spread through compromised devices, software, or networks connected to broader criminal ecosystems.

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.