Eternity Project on Telegram: 2026 Status of the Malware Shop

8 sources
Comments (0)

Eternity Project in 2026: the short answer

The Eternity Project, also called EternityTeam, was a malware-as-a-service shop that sold modules through a Telegram channel and a Tor site. Researchers say it was active since at least January 2022.[6][7] Its last widely reported product was LilithBot, a bot with stealer, clipper and miner functions that Zscaler described in October 2022.[6]

We found no new public research on Eternity as a group after 2022 in our searches, and no report of arrests. That does not mean the code is gone. Leaked or resold builds can circulate for years, and the model it used, where stolen data goes straight to a Telegram bot, is still common. In August 2025, for example, SentinelLabs described PXA Stealer and its Telegram-powered ecosystem.[8]

Eternity Project at a glance
QuestionAnswer
What it wasA malware-as-a-service shop run by a group researchers call EternityTeam[6][7]
Active sinceAt least January 2022[6][7]
Where it soldA Telegram channel, a Tor site and several cybercrime forums[6][7]
ModulesStealer, miner, clipper, ransomware, worm with dropper, DDoS bot[6]
Later productLilithBot, a multi-function bot reported in October 2022[6]
Status in 2026We found no new public reports on the group after 2022

Timeline: from forum launch to LilithBot

Timeline of the Eternity Project malware-as-a-service from its January 2022 launch on Telegram and forums to the LilithBot report in October 2022
Eternity Project timeline, 2022. Sources: Sekoia, Zscaler, SentinelLabs.
Dated events around the Eternity Project
DateEvent
January 2022EternityTeam begins developing and selling malware[7]
Early February 2022Administrators of several cybercrime forums verify and approve the project[7]
April 12, 2022Sekoia sends its first private report on the group to clients[7]
May 17, 2022Sekoia publishes its public analysis of EternityTeam[7]
October 5, 2022Zscaler ThreatLabz publishes its analysis of LilithBot, sold by the Eternity group[6]
August 4, 2025SentinelLabs describes PXA Stealer and its Telegram-powered ecosystem, a similar model[8]

What changed since 2022

Our original report below lists the prices that were public in May 2022. Researchers saw the price list move over time. Sekoia recorded the stealer at $99 per month, the clipper at $99, the miner at $110, a botnet and dropper at $150 per month, and the worm at $300.[7] Zscaler later described an Eternity subscription model with prices between $90 and $470.[6]

The group also bundled its tools. Zscaler's July 2022 finding, LilithBot, combined a stealer, a clipper and a miner in one bot, with persistence, anti-debug and anti-virtual-machine checks. It uploaded stolen data as a zip file to its command server.[6] Zscaler linked the Eternity group to the Russian "Jester Group".[6]

Sekoia found real infection lures too. Samples were spread as fake Growtopia glitch tools and cracked game hacks, and the stealer targeted browsers, crypto wallets, password managers, messengers, VPN and FTP clients and gaming accounts. Stolen data went to Eternity servers and was then forwarded to the buyer's Telegram bot.[7] The group advertised on forums such as XSS, BHF and RuTOR.[7]

Risks around "Eternity" files on Telegram (our analysis)

Many people reach this page while looking for something called "Eternity" on Telegram or on file hosting sites. The name is used by many unrelated channels, so we cannot say what each one is. Our analysis of the risk is simple: the Eternity malware was spread exactly through this kind of download.

  • Game cheats and glitch tools. Sekoia found Eternity samples disguised as Growtopia hacks.[7] Any free cheat file can hide a stealer.
  • Cracked software and APK files. An "Eternity project apk" or a cracked app from a file host is a common carrier for stealers and clippers.
  • Files shared in Telegram groups. Telegram is not a virus by itself, but files posted in open channels are not checked. Yes, you can get a virus by running a file you got on Telegram.
  • Clipboard tricks. A clipper swaps a copied crypto address with the attacker's address, so payments go to the wrong wallet.
  • Fake "crypto" projects. Searches for "Eternity crypto" can lead to token pages and wallet connect sites. Treat unknown ones as possible scams.

What to do if you ran a suspicious Eternity file

Six steps after running a suspicious Eternity file in 2026: disconnect, scan, change passwords, secure crypto wallets, end sessions, watch accounts
Six steps after running a suspicious file from Telegram. 2-Spyware, 2026.

1. Disconnect. Take the computer offline. A stealer sends data within seconds, but a miner or bot keeps talking to its server.

2. Scan the system. Run a full scan with a trusted security tool. Our virus removal guides explain how to clean stealers, miners and clippers.

3. Change passwords. Do it from a clean device. Start with email, then banking, then social and gaming accounts. Turn on two-factor sign-in.

4. Secure wallets. If a crypto wallet was on the machine, create a new wallet with a new seed phrase on a clean device and move the funds. Stealers target wallets and browser wallet extensions.[7]

5. End sessions. Stolen cookies can keep a thief logged in after a password change. Use "log out of all devices" in Telegram, Discord, Google and similar services.

6. Watch accounts. Check bank statements and see whether your email appears in a leak with our leak check.

What is still unknown

  • Who ran EternityTeam. Researchers linked it to the Jester Group, but no names were published.[6]
  • Whether the shop still sells today. We found no public report on it after 2022.
  • How many victims Eternity tools infected. We found no count.

Our original 2022 report

The text below is our report as first published in 2022. We keep it unchanged for the record; the sections above bring it up to date.

Threat actors launched the Eternity Project malware-as-a-service that offers to purchase the malware toolkit which can be customized with particular modules based on the attack that is launched. The malicious toolkit includes the info-stealer code, cryptocurrency miner, clipper, and ransomware programs.[1] it also has a worm spreader and DDoS bot. These tools can be purchased as separate tools.[2]

The developer sells the Stealer module for $260 as an annual subscription. The Eternity Stealer steals passwords, cookies, credit cards, and crypto-wallets from the victim's machine and sends them to the TA's Telegram Bot.

The unidentified attackers have been linked to the active malware toolkit in development. The distribution allows professional and amateur cybercriminals to purchase these tools for their malicious campaigns.[3] besides using the Telegram channel to communicate with the community and post updates about the features and functions, the attackers also use the Telegram bot that allows buyers to build the binary.

The criminal behind this toolkit provides the option in the channel to customize the binary features. It is an effective way to build binaries without dependencies, researchers[4] say. The particular Telegram channel has more than 500 members.

Malicious functions and tools

Eternity Stealer is the threat sold for $260 for the annual subscription. This tool siphons passwords, cookies, credit card details, browser cryptocurrency extensions, crypto wallets, and VPN clients. it can Gather data from email apps on the machine and send the information to the Telegram bot.

Eternity Miner is sold for $90 as an annual subscription. It abuses the resources of computers and runs on the compromised machine to mine money. Eternity Clipper is sold for $110. it is the crypto-clipping program that steals cryptocurrency during transactions with original wallet addresses saved in the clipboard. It changes the original address with the attacker's wallet address.

Eternity Ransomware costs $490. This is a 130kb ransomware virus executable that encrypts all of the files on victims' computers to have the purpose for the ransom demands. Eternity Worm costs $390 and propagates via USB drivers, network shares, local files, and spam messages on Discord, and Telegram. Eternity DDoS bot is the feature that is under development.

Additional details

The most expensive toolkit is the ransomware module that runs for $490, and it supports offline encryption using the mix of RSA and AES encryption algorithms.[5] It can lock documents, photos, databases, and archives. Authors of this malware claim that the ransomware payload is undetectable. They also state that Virus Total results show the payload is detected by none of the particular AV tools.

This cryptovirus also offers the option to set the timer that renders these files completely and data is no longer recoverable once the time expires. This is the feature that helps to pressure victims to pay the demanded ransom as quickly as possible. It is observed that Eternity Stealer already is copying the code of other malware pieces that are placed on GitHub. Modifications and rebranding get played to sell it on the Telegram for profit.

Researchers state that this cybercrime when the Telegram channels and other cybercrime forums are used to sell malicious programs and other products becoming more popular. There is a significant increase in such attacks and cybercrime. The additional instructions that creators place on their channels makes this malware kit a severe threat because even inexperienced hackers can purchase and learn how to use the malware.

Frequently asked questions

What is Eternity on Telegram?

The Eternity Project was a malware shop that used a Telegram channel to sell stealers, miners, clippers, ransomware, a worm and a DDoS bot.{6}{7} Buyers could build their own malware file through a Telegram bot. Many unrelated Telegram channels also use the name Eternity, so the name alone does not tell you what a channel is.

Is the Eternity Project still active in 2026?

We found no public research on the group after 2022. Its last reported product was LilithBot, described by Zscaler in October 2022.{6} Old builds can still circulate, and the same Telegram-based model is used by newer stealers such as PXA Stealer, reported in August 2025.{8}

What does Eternity Stealer steal?

Eternity Stealer takes browser passwords, cookies, saved cards, autofill data and history, plus crypto wallets and browser wallet extensions.{7} It also targets password managers, messengers, VPN and FTP clients and gaming accounts. The stolen data was forwarded to the buyer's Telegram bot.

Can you get a virus from Telegram?

Yes, if you open or run a file that someone shared there. Telegram does not check files posted in open groups, and the Eternity malware was itself sold and built through Telegram.{6} Messages alone are not the danger; downloaded programs, APK files and cracks are.

Is the Eternity project APK safe?

Treat any APK called "Eternity project" from Telegram or a file host as unsafe. We could not verify any such app, and the Eternity name is linked to a known malware shop.{6} Install apps only from official stores and scan any file you already opened.

What is LilithBot?

LilithBot is a multi-function malware bot sold by the Eternity group, found by Zscaler ThreatLabz in July 2022.{6} It combines a stealer, a clipper and a miner, uses anti-debug and anti-virtual-machine checks, and uploads stolen data as a zip file to its server.

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year