Qrator Research Lab has reported the discovery of a new botnet architecture that significantly complicates traditional law enforcement and cybersecurity responseQrator Research Lab has reported the discovery of a new botnet architecture that significantly complicates traditional law enforcement and cybersecurity response

Qrator Identifies Polygon-Powered Botnet Hard to Shut Down

2026/02/27 16:04
4 min read

Qrator Research Lab has reported the discovery of a new botnet architecture that significantly complicates traditional law enforcement and cybersecurity response efforts. The finding highlights a growing shift in how cybercriminals design command-and-control systems, moving away from centralized infrastructure toward decentralized blockchain networks that are far more difficult to disrupt.

Historically, dismantling botnets followed a familiar pattern. Investigators would identify the central server issuing commands to infected machines and then shut it down or redirect the malicious traffic to controlled environments. According to Qrator’s research, this approach is becoming less effective as attackers adopt technologies that remove the single point of failure that authorities typically target.

How Aeternum C2 Operates on Blockchain Infrastructure

The newly identified botnet, known as Aeternum C2, does not rely on a central command server. Instead, it publishes operational instructions directly to the Polygon blockchain. Because blockchain data is distributed across thousands of computers globally and replicated simultaneously, there is no single location that can be seized or shut down.

Researchers explained that Aeternum functions as a loader written in C++ and is compatible with most Windows-based systems. Once a device is infected, it no longer connects to a traditional website or server for instructions. Instead, it queries the blockchain for smart contracts, which are immutable digital instruction sets stored permanently on the network. This design ensures that the botnet’s command logic remains accessible as long as the blockchain itself is operational.

Eliminating the Traditional Off Switch

Qrator’s analysis showed that the botnet operator can manage the entire operation through a simple web-based dashboard. Commands issued through this interface are written to the blockchain and then retrieved by infected machines worldwide. Because all communication flows through the blockchain, there is no core infrastructure for authorities to dismantle.

The system is also highly efficient. Most compromised devices reportedly receive updated instructions within two to three minutes. The operator can issue a variety of payloads, including tools designed to steal digital assets or software that hijacks computing power for unauthorized cryptocurrency mining. This rapid and flexible command delivery further increases the botnet’s effectiveness.

More Resilient Than Previous Blockchain-Based Threats

Previous botnets, such as Glupteba, incorporated blockchain technology only as a fallback mechanism. Those networks could still be disrupted by targeting their primary servers. In contrast, Qrator researchers observed that Aeternum is built entirely around blockchain infrastructure, making it far more resistant to takedown efforts. With no servers to seize and no domain names to block, traditional countermeasures become largely ineffective.

The researchers also noted that operating costs for the attackers are extremely low. Sending hundreds of commands to thousands of infected machines reportedly costs only a minimal amount in transaction fees. This low barrier to operation makes the model accessible and scalable for cybercriminal groups.

Evasion Techniques and Long-Term Risks

Further investigation revealed that the malware includes anti-virtual machine techniques. These mechanisms allow the software to detect when it is being analyzed in a controlled research environment. If such conditions are detected, the malware simply refuses to execute, limiting the ability of security teams to study its behavior in detail.

The long-term implications of this model are particularly concerning. A blockchain-based command structure allows botnets to persist for extended periods and scale more easily, making them well-suited for large-scale distributed denial-of-service attacks. Even if individual devices are cleaned, the same blockchain-hosted instructions can be reused to reestablish control, reducing the effectiveness of traditional remediation efforts.

Shifting the Focus of Cyber Defense

Qrator’s findings suggest that defenders may need to rethink their approach to botnet mitigation. Rather than focusing solely on taking down command servers, organizations may need to prioritize filtering malicious traffic before it reaches critical infrastructure. As blockchain-based command-and-control systems gain traction among attackers, proactive traffic analysis and network-level defenses are likely to become essential components of modern cybersecurity strategies.

The post Qrator Identifies Polygon-Powered Botnet Hard to Shut Down appeared first on CoinTrust.

Market Opportunity
Farcana Logo
Farcana Price(FAR)
$0.001014
$0.001014$0.001014
-5.32%
USD
Farcana (FAR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Tokyo’s Metaplanet Launches Miami Subsidiary to Amplify Bitcoin Income

Tokyo’s Metaplanet Launches Miami Subsidiary to Amplify Bitcoin Income

Metaplanet Inc., the Japanese public company known for its bitcoin treasury, is launching a Miami subsidiary to run a dedicated derivatives and income strategy aimed at turning holdings into steady, U.S.-based cash flow. Japanese Bitcoin Treasury Player Metaplanet Opens Miami Outpost The new entity, Metaplanet Income Corp., sits under Metaplanet Holdings, Inc. and is based […]
Share
Coinstats2025/09/18 00:32
UK Looks to US to Adopt More Crypto-Friendly Approach

UK Looks to US to Adopt More Crypto-Friendly Approach

The post UK Looks to US to Adopt More Crypto-Friendly Approach appeared on BitcoinEthereumNews.com. The UK and US are reportedly preparing to deepen cooperation on digital assets, with Britain looking to copy the Trump administration’s crypto-friendly stance in a bid to boost innovation.  UK Chancellor Rachel Reeves and US Treasury Secretary Scott Bessent discussed on Tuesday how the two nations could strengthen their coordination on crypto, the Financial Times reported on Tuesday, citing people familiar with the matter.  The discussions also involved representatives from crypto companies, including Coinbase, Circle Internet Group and Ripple, with executives from the Bank of America, Barclays and Citi also attending, according to the report. The agreement was made “last-minute” after crypto advocacy groups urged the UK government on Thursday to adopt a more open stance toward the industry, claiming its cautious approach to the sector has left the country lagging in innovation and policy.  Source: Rachel Reeves Deal to include stablecoins, look to unlock adoption Any deal between the countries is likely to include stablecoins, the Financial Times reported, an area of crypto that US President Donald Trump made a policy priority and in which his family has significant business interests. The Financial Times reported on Monday that UK crypto advocacy groups also slammed the Bank of England’s proposal to limit individual stablecoin holdings to between 10,000 British pounds ($13,650) and 20,000 pounds ($27,300), claiming it would be difficult and expensive to implement. UK banks appear to have slowed adoption too, with around 40% of 2,000 recently surveyed crypto investors saying that their banks had either blocked or delayed a payment to a crypto provider.  Many of these actions have been linked to concerns over volatility, fraud and scams. The UK has made some progress on crypto regulation recently, proposing a framework in May that would see crypto exchanges, dealers, and agents treated similarly to traditional finance firms, with…
Share
BitcoinEthereumNews2025/09/18 02:21
WTI Crude Oil Plummets Near $65.50 as Crucial US-Iran Talks Progress

WTI Crude Oil Plummets Near $65.50 as Crucial US-Iran Talks Progress

BitcoinWorld WTI Crude Oil Plummets Near $65.50 as Crucial US-Iran Talks Progress Global energy markets witnessed significant volatility this week as West Texas
Share
bitcoinworld2026/02/27 18:45