BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Permanent Threat: Analyzing Aeternum’s Blockch
 ain-Based\n   C2 Operations and Communications\n   Tags: Malware Village |
  Creator Talk/Panel\n   When: Saturday\, Aug 8\, 14:40 - 15:15 PDT\n   Whe
 re: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - [1]Map\n\n   Descri
 ption:\n\n   In recent years\, threat actors have been migrating their\n  
  command-and-control infrastructure from traditional domains and\n   serve
 rs to decentralized platforms that are resilient to takedowns.\n   The Pol
 ygon blockchain is one such platform\, where encrypted and\n   plaintext i
 nstructions can be embedded into immutable smart contracts\,\n   making th
 em permanently accessible and beyond the reach of law\n   enforcement seiz
 ure. Aeternum is a recently discovered botnet that\n   takes full advantag
 e of this shift. Its operators write encrypted C2\n   commands directly in
 to smart contracts\, and infected machines retrieve\n   them via public Re
 mote Procedure Call (RPC) endpoints\, eliminating the\n   need for any att
 acker-controlled server in the command delivery chain.\n\n   This one-way\
 , read-only design functions as a dead-drop resolver that\n   cannot be ta
 ken offline through conventional means. The botnet's reach\n   extends bey
 ond a single malware family. Multiple samples across\n   different languag
 es and capabilities like loaders\, stealers\, RATs\, and\n   cryptominers 
 have been found querying the same smart contract\n   infrastructure using 
 a shared function selector. Each brings its own\n   execution techniques\,
  from Early Bird APC injection and multi-layer\n   encryption to Telegram-
 based exfiltration and sandbox evasion routines\n   targeting analyst envi
 ronments.\n\n   By analyzing malware behaviors\, network traffic\, decrypt
 ing the\n   on-chain payloads\, and following the operator's digital footp
 rint\n   across multiple platforms\, we were able to trace the infrastruct
 ure\n   back to a single infrastructure. In this talk\, we will walk throu
 gh\n   the full investigation from initial sample discovery to on-chain\n 
   decryption and operator attribution and discuss what defenders need to\n
    know to detect blockchain-based C2 at the network level.\n\n   Speakers
 :Chris Navarrete\,Sai Sathvik Ruppa\n\n   SpeakerBio:  Chris Navarrete\, S
 enior Principal Security Researcher -\n   CDSS Advanced Threat Prevention 
 (ATP) at Palo Alto Networks\n\n   Chris Navarrete is a Senior Principal Se
 curity Researcher within the\n   Advanced Threat Prevention team at Palo A
 lto Networks. His work\n   centers on cutting-edge research in cybersecuri
 ty\, particularly in\n   threat detection and malware analysis. Previously
 \, he served as an\n   adjunct professor of computer science at San Jose S
 tate University\,\n   teaching Software Security Technologies. He holds a 
 Master of Science\n   in software engineering with a specialization in cyb
 ersecurity from\n   San Jose State University. Chris has presented at majo
 r industry\n   conferences\, including Black Hat Asia\, the Computer Antiv
 irus Research\n   Organization (CARO)\, the Cyber Threat Alliance's Threat
  Intelligence\n   Practitioners (TIPS) conference\, and Black Hat Arsenal\
 , where he\n   introduced and released BLACKPHENIX — a framework designe
 d to\n   automate malware analysis workflows.\n\n   SpeakerBio:  Sai Sathv
 ik Ruppa\, Staff Security Researcher at Palo Alto\n   Networks\n\n   Sai S
 athvik Ruppa is a Staff Security Researcher at Palo Alto Networks\n   and 
 a recent M.S. graduate in Information Security from Carnegie\n   Mellon Un
 iversity. He specializes in vulnerability detection and\n   malware analys
 is\, leveraging his expertise to identify\, analyze\, and\n   mitigate adv
 anced cyber threats.\n\n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20260808T221500Z
DTSTART:20260808T214000Z
LOCATION:Malware Village - LVCCW Level 1 Hall 2 600 (Malware Village) Talks
SUMMARY:The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Op
 erations and Communications
END:VEVENT
END:VCALENDAR
