State-Linked Hackers Drive 420% Surge in Onchain Malware Activity

Published:

Hackers linked to North Korea and Iran are increasingly using public blockchains to support malware operations, according to new research from Chainalysis. The firm said activity involving malware instructions or infrastructure stored on blockchains rose 420% over the past 12 months.

The findings highlight a growing cybersecurity risk for the cryptocurrency industry. Attackers can use blockchain networks to store instructions that malware retrieves later, creating infrastructure that is difficult to remove or disrupt.

State Actors Expand Blockchain Use

State-linked groups accounted for roughly two-thirds of new blockchain dead drop activity each quarter by the second quarter of 2026, Chainalysis said. The research identified North Korean and Iranian operators among the groups adopting the technique.

North Korea-linked activity demonstrates how attackers can spread their infrastructure across multiple networks. Chainalysis linked previously unattributed activity involving Tron, Aptos and BNB Smart Chain to UNC5342, a group tracked by Google Threat Intelligence.

The campaign used transactions on Tron and Aptos to direct infected devices toward information stored on BNB Smart Chain. The blockchain data contained encrypted configuration details and server addresses used by the malware.

Iran-Linked Activity Targets Bitcoin

Iran-linked operators have used a different approach. Chainalysis identified activity in which operational instructions were embedded inside Bitcoin transactions.

This method takes advantage of blockchain permanence. Traditional command-and-control infrastructure can be disrupted through server seizures or domain takedowns. Data recorded on a public blockchain remains accessible after it is published.

The technique can support malware campaigns involving credential theft, remote access and data extraction. Chainalysis said it has identified more than 15 campaigns and threat-actor clusters using blockchain dead drops.

The rise also creates a challenge for cryptocurrency companies and cybersecurity teams. Blocking the underlying blockchain data may not be practical because public networks are designed to preserve transaction information.

Instead, Chainalysis said detection and attribution remain key defenses. Analysts can examine blockchain activity, wallet relationships and transaction histories to identify infrastructure associated with malicious campaigns.

Adam L
Adam L
In the world of blockchain and cryptocurrencies, I have a great deal of passion and interest. My interest in blockchain and cryptocurrencies has led me to explore these technologies in greater depth, as I am interested in the potential implications they could have on the global economy.

Related News

Recent