LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

State-Linked Hackers Fuel 420% Surge in Onchain Malware Activity, Chainalysis Reports

Cointelegraph · Ezra Reguerra

Analytical firm Chainalysis has identified a 420% increase over the past year in malware instructions and infrastructure data being stored on public blockchains, predominantly by state-linked hackers. These groups accounted for roughly two-thirds of new onchain malware activities each quarter. Among the state actors detected are operators linked to North Korea and Iran, who leverage blockchain technology as a resilient platform to manage malware campaigns and conduct data theft.

Activity of North Korea- and Iran-Linked Groups

Chainalysis identified that among state-linked hackers, operators associated with North Korea and Iran were particularly active. The firm linked onchain activity across the Tron, Aptos, and BNB Smart Chain (BSC) blockchains to UNC5342, a North Korean-affiliated group tracked by Google Threat Intelligence.

Transactions on Tron and Aptos contained encoded pointers directing infected devices to a specific BSC transaction. Tron served as the primary routing path, with Aptos as a fallback. The BSC transaction housed encrypted server addresses and configuration data, connecting compromised machines to offchain infrastructure used for remote access and data theft.

Advantages of Using Blockchain for Malware Management

Chainalysis explained that storing instructions on public blockchains increases the durability of malware campaigns because the data remains accessible even after domains, servers, or code repositories are taken down.

In 2025, North Korean hackers employed a similar method known as EtherHiding, embedding crypto-stealing code within Ethereum smart contracts.

Surge in Malicious Writes and the Role of Artificial Intelligence

Since July 2025, Chainalysis recorded a 440% increase in malicious blockchain writes. The firm attributes this surge partly to the advent of high-capacity open-source Chinese AI models capable of generating malicious code with limited safeguards.

Eric Jardine, Chainalysis’ cybercrimes research lead, told Cointelegraph that while there is a clear temporal correlation, no direct evidence confirms that these specific AI models were used by threat actors to amplify their output.

Iran-Linked Actors Use Bitcoin Blockchain for Malware Instructions

Chainalysis also identified threat actors suspected to be linked to Iran’s Ministry of Intelligence who encoded command-and-control routing data onto the Bitcoin blockchain.

This assessment was based not solely on onchain activity but also on the malware family, decoding techniques, timing, and server infrastructure associated with previously documented Iranian operations.

Attacker-controlled wallets sent small payments to a well-known Bitcoin address historically tied to Bitcoin creator Satoshi Nakamoto. Though unconnected to the attackers, this address functioned as a permanent public point from which infected devices could retrieve updated commands.

By publishing new Bitcoin transactions, the attackers could alter their server infrastructure, with infected machines automatically retrieving these new instructions. Subsequent operations moved offchain and potentially included remote access, credential theft, and deployment of additional malware.

Why it matters

The increase in activity from state-sponsored hacking groups leveraging public blockchains to store malware instructions reflects the growing sophistication and resilience of modern cyberattacks. Utilizing blockchain technology enables attackers to maintain control over compromised devices even after traditional domains or servers are taken down, complicating detection and eradication efforts. The rise of such techniques, along with the possible influence of artificial intelligence advancements in accelerating malicious code generation, highlights emerging challenges for digital security and underscores the need for adaptive, strengthened cybersecurity measures.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗