📈 Get daily crypto insights that make you smarter about your money

State Hackers Drive 420% Surge in Onchain Malware as North Korea and Iran Abuse Public Blockchains

State-linked hacking groups now account for roughly two-thirds of new malicious activity each quarter on public blockchains, according to a new Chainalysis report that documents a 420% surge over the past 12 months in the number of times attackers stored malware instructions or infrastructure information directly onchain.

The findings, published Thursday by the blockchain analytics firm, describe a rapidly maturing tradecraft in which public blockchains are abused as resilient dead-drop infrastructure, turning the immutability that underpins crypto networks into a weapon for distributing and maintaining malware campaigns.

## North Korea’s multi-chain malware relay

Among the report’s most significant attributions, Chainalysis connected previously unattributed activity spanning Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked threat group tracked by Google Threat Intelligence.

The operation worked as a layered relay. Encoded pointers embedded in Tron and Aptos transactions directed infected devices to the same BNB Smart Chain transaction, with Tron serving as the primary route and Aptos as a fallback. The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.

Chainalysis noted that storing payload directions on public blockchains dramatically increases the durability of malware campaigns, because the stored information remains permanently accessible even after domains, servers or code repositories are seized or taken down. The technique echoes EtherHiding, a method North Korean hackers used in 2025 to place crypto-stealing code inside smart contracts.

## Iran-linked actors used a Satoshi-era address as a bulletin board

The report also identified threat actors suspected of links to Iran’s Ministry of Intelligence writing encoded command-and-control routing data onto the Bitcoin blockchain. Chainalysis said its assessment rested on the malware family, decoding method, timing and server infrastructure associated with previously reported Iranian operations, rather than the blockchain activity alone.

The Iranian operation exploited one of the Bitcoin network’s most famous addresses. Attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to creator Satoshi Nakamoto, a destination the report stressed had no connection to the attackers. The address simply served as a permanent, public location that infected devices could reliably check for updated directions.

By publishing a new Bitcoin transaction, the operators could rotate their server infrastructure at will, and infected devices would automatically retrieve the fresh configuration. Once equipped with those instructions, the malware moved offchain for its actual work, which Chainalysis said could include remote access, credential theft and delivery of additional malicious payloads.

## AI models accelerate the onslaught

The state actors are being supercharged by artificial intelligence. Chainalysis recorded a 440% increase in malicious blockchain writes since July 2025, a period coinciding with the emergence of high-capacity open-source Chinese AI models capable of producing malicious code with limited built-in safeguards.

Eric Jardine, cybercrimes research lead at Chainalysis, told Cointelegraph the firm found a “clear point-in-time association” between the availability of these models and the surge in output, though he cautioned the company could not prove that the actors publishing the malicious transactions had specifically used the models.

For blockchain platforms, the report arrives as an unwelcome compliance burden. The malicious writes are ordinary transactions from the network’s perspective, indistinguishable at the protocol level from legitimate activity, meaning neither Tron, Aptos, BNB Smart Chain nor Bitcoin can filter them out without abandoning the openness that defines them.

## An arms race on transparent rails

The report crystallizes an uncomfortable irony at the heart of blockchain security. The same public, permanent, censorship-resistant properties that make blockchains trustworthy financial ledgers make them exceptionally useful command-and-control channels, since no hosting provider can be pressured into removing the data and no takedown can erase it.

For defenders, the transparency cuts both ways. Onchain malware writes are visible to everyone, including the analytics firms and threat intelligence teams racing to decode and attribute them. Chainalysis’s ability to tie multi-chain dead drops to UNC5342 and to flag suspected Iranian ministry activity demonstrates that blockchain forensics can keep pace, at least for now.

But the economics favor the attackers, who need only embed a few hundred bytes of encoded data to maintain global malware infrastructure, while attribution requires stitching together cross-chain patterns, offchain server records and prior campaign histories. With state budgets behind two-thirds of quarterly activity and AI models collapsing the cost of producing malicious code, the volume of onchain malware writes is likely to keep climbing, turning every major smart contract platform into contested ground in a low-level cyber conflict that never leaves a paper trail, only a block trail.

10 thoughts on “State Hackers Drive 420% Surge in Onchain Malware as North Korea and Iran Abuse Public Blockchains”

  1. 420% surge in a year and state groups behind two thirds of new malicious activity per quarter. the UNC5342 attribution across three chains is solid work from chainalysis

  2. state actors using public chains as c2 dead drops is such an obvious move in hindsight. immutable malware config that nobody can take down, 420% surge tracks

    1. the fun part is you literally cannot censor it without breaking the chain itself. two thirds of new malicious activity per quarter, wild

  3. The attribution spanning Tron, Aptos and BNB Chain is the detail people should focus on. This is every major chain, not some fringe network problem.

    1. exactly, aptos getting lumped in with tron and BNB kills the whole its only old chains cope. newer L1s inherit the exact same dead drop problem

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,349.00+0.9%ETH$2,451.54+2.7%SOL$100.25+3.4%BNB$724.79+2.1%XRP$1.30+2.4%ADA$0.2007+5.1%DOGE$0.0812+2.8%DOT$1.03+6.2%AVAX$7.53+4.1%LINK$11.27+5.4%UNI$7.20+17.4%ATOM$1.53+3.4%LTC$52.93+5.2%ARB$0.1634+2.2%NEAR$2.84+16.3%FIL$0.8153+5.3%SUI$0.7260+6.1%BTC$76,349.00+0.9%ETH$2,451.54+2.7%SOL$100.25+3.4%BNB$724.79+2.1%XRP$1.30+2.4%ADA$0.2007+5.1%DOGE$0.0812+2.8%DOT$1.03+6.2%AVAX$7.53+4.1%LINK$11.27+5.4%UNI$7.20+17.4%ATOM$1.53+3.4%LTC$52.93+5.2%ARB$0.1634+2.2%NEAR$2.84+16.3%FIL$0.8153+5.3%SUI$0.7260+6.1%
Scroll to Top