What is at stake is plain and immediate: a botnet loader has been observed using the Polygon blockchain's smart contracts to run its command-and-control and to execute payloads, a configuration that shifts parts of malware operations onto decentralized infrastructure.
Aeternum botnet loader
Unit 42 identifies the threat as the Aeternum botnet loader. The published analysis characterizes Aeternum as a loader that leverages blockchain technology as part of its operational design. Beyond the name and role — loader — the report connects Aeternum directly to a distinctive method of communications and control.
Polygon blockchain smart contracts as an operational vector
Unit 42 states that Aeternum leverages Polygon blockchain smart contracts. That fact locates a key element of the threat on a public blockchain platform: smart contracts on Polygon are used by Aeternum as an operational surface. The report describes those smart contracts as integral to how the loader conducts its activities.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDecentralized command-and-control infrastructure
According to Unit 42, Aeternum uses the blockchain-hosted smart contracts to create decentralized command-and-control (C2) infrastructure. The characterization of the C2 as decentralized is explicit in the source: the botnet’s communications and control mechanisms are not relying on a single, centrally hosted server, but rather on contracts deployed to the Polygon blockchain.
Payload execution via blockchain-hosted mechanisms
The Unit 42 analysis further states that Aeternum uses Polygon smart contracts for payload execution. The report connects the blockchain components not only to communications and control, but also to steps in the delivery and execution chain where code or actions that further the botnet’s aims are enacted.
What this means for security teams, policymakers, and enterprises
- Security teams: Watch for Aeternum’s use of Polygon smart contracts as an explicit transport and execution mechanism. Unit 42’s description links the loader to on-chain contracts, which means detection and response workflows may need to consider blockchain artifacts alongside traditional network and host indicators.
- Policymakers and regulators: Unit 42’s finding that a loader is using Polygon smart contracts for decentralized C2 and payload execution highlights a convergence of public blockchain infrastructure and malicious tooling that regulators may need to examine when evaluating oversight, reporting, or coordination frameworks tied to abuse of blockchain platforms.
- Enterprises and procurement leaders: The report’s identification of blockchain-hosted C2 and execution in the Aeternum loader signals a practical consideration for vendor security assessments and supply-chain risk reviews: public smart contracts and their lifecycle can be part of a threat actor’s operational footprint.
Unit 42’s post, titled "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications," frames a concise but consequential finding: Aeternum is a loader that uses Polygon smart contracts to provide decentralized command-and-control and to execute payloads. The linkage of a botnet loader to public smart contracts reframes a part of the defensive problem onto a platform not traditionally treated as an active actor in malware operations.
For readers who want the technical breakdown and the primary analysis, see the original Unit 42 report: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/




