Skip to main content

State-Linked Hackers Fuel 420% Jump in On-Chain Malware, Chainalysis Finds



State-linked cybercriminals are increasingly using public blockchains as “dead drops” for malware instructions and infrastructure details, according to a new Chainalysis report. The firm estimates that state-aligned actors accounted for roughly two-thirds of new dead drop activity each quarter, while the frequency of these writes rose 420% over the past 12 months.


Chainalysis also reports that operators tied to North Korea and Iran are among the groups adopting the tactic, including activity it linked across multiple networks—Tron, Aptos, and BNB Smart Chain (BSC)—to a North Korea-associated actor tracked by Google Threat Intelligence.



Key takeaways



  • Chainalysis says state-linked threat actors drive about two-thirds of quarterly blockchain dead drop activity.

  • Blockchain “dead drop” writes climbed 420% year over year, indicating faster growth in on-chain malware infrastructure.

  • North Korea-linked groups have used multi-chain routing, with Tron acting as a first route and Aptos as a fallback to a BSC transaction containing encrypted instructions.

  • Chainalysis attributes a 440% rise in malicious writes since July 2025 in part to the availability of high-capacity open-source AI models capable of generating malicious code with limited safeguards.

  • Iran-linked operators are also suspected of using the Bitcoin blockchain to publish encoded command-and-control routing data that infected devices can poll for updates.



Dead drops across public chains: why it’s hard to shut down


Chainalysis defines the “dead drop” tactic as embedding malware guidance—such as pointers to infrastructure, server addresses, or configuration data—inside transactions on public blockchains. The report highlights a central advantage for attackers: even if domains, servers, or code repositories are taken offline, the stored information can remain publicly accessible on-chain.


The analytics firm warns that this durability makes campaigns more resilient over time and increases the operational burden on defenders. Instead of merely disrupting a single server or endpoint, response efforts may need to account for information that is permanently replicated across decentralized ledgers.


Chainalysis also points to a broader pattern: state actors are not only using blockchains, but increasingly scaling how often they do so and broadening the networks involved.



North Korea-linked activity routed through Tron, Aptos, and BSC


One of the report’s most specific findings ties previously unattributed blockchain activity spanning Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.


Chainalysis describes how encoded pointers embedded in Tron and Aptos transactions would direct infected devices toward the same BSC transaction. In this setup, Tron served as the first routing path, while Aptos provided a fallback option if the primary route failed.


The shared BSC transaction, Chainalysis says, contained encrypted server addresses and configuration data. That data, once decrypted by compromised devices, connected them to off-chain infrastructure used for remote access and data theft.


For investors and builders, the takeaway is less about any single chain and more about how malware operators are treating blockchain networks as flexible, multi-route messaging systems—one that can help keep campaigns functioning even when certain routes or infrastructure components change.


Chainalysis also notes that public blockchains have previously been used in similar ways by North Korean hackers. In 2025, for instance, coverage from Cointelegraph described a technique called EtherHiding, where malicious crypto-stealing code was placed in smart contracts.



AI’s role: more malicious writes, but attribution remains uncertain


Chainalysis further reports a 440% increase in malicious blockchain writes since July 2025, framing the change as coinciding with when “high-capacity open-source Chinese artificial intelligence models became capable of producing malicious code with limited safeguards,” according to the firm’s findings.


Eric Jardine, cybercrimes research lead at Chainalysis, told Cointelegraph that the team observed a “clear point-in-time association” between the period and the surge in malicious on-chain activity. However, he cautioned that the firm could not prove that the actors publishing the malicious transactions and contracts had directly used these AI models to boost their output.


This distinction matters for what readers should infer from the data. The increase suggests that the environment for writing and deploying malicious code may have become easier to scale, but Chainalysis’ evidence does not establish a direct line from a specific model to specific actors. Defenders may still adjust their priorities—especially around how quickly adversaries can publish new payloads—without assuming the attribution is solved.



Iran-linked operations use Bitcoin as an update channel


Beyond non-Bitcoin networks, Chainalysis also identifies threat actors it suspects are linked to Iran’s Ministry of Intelligence. In its assessment, those actors wrote encoded command-and-control routing data to the Bitcoin blockchain.


Chainalysis says its judgment is based on a combination of factors—such as the malware family, the decoding method used, timing patterns, and associated server infrastructure—rather than relying on blockchain activity alone.


The report describes a mechanism where attacker-controlled wallets sent small payments to a well-known Bitcoin address historically tied to Satoshi Nakamoto. Chainalysis states that the address has no connection to the attackers and functions as a permanent public location that infected devices can check for updated instructions.


According to Chainalysis, the attackers can refresh their server infrastructure by publishing a new Bitcoin transaction with updated data. Once malware pulls the new directions, the operation can shift off-chain for follow-on activities that may include remote access, credential theft, and the delivery of additional malware.


By using Bitcoin as a reliable public registry for routing updates, the approach again underscores the same theme: attackers can avoid some traditional single-point failures (like takedowns) by embedding “where to go next” information into data that remains widely available.



Chainalysis’ findings suggest defenders should treat blockchain dead drops as an evolving, potentially scalable part of cyber operations—especially as on-chain writes rise across multiple networks. The key uncertainty readers should watch next is whether future reporting will narrow the gap between association and direct attribution—particularly around AI-assisted scaling—and how quickly defenders and platforms adapt to this more resilient style of malware infrastructure.



https://www.cryptobreaking.com/state-linked-hackers-fuel-420/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=State-Linked%20Hackers%20Fuel%20420%%20Jump%20in%20On-Chain%20Malware,%20Chainalysis%20Finds%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

XRP vs. SOL: Massive Market Interest Gap Revealed by Exec

Here's the revised article with an introduction, key takeaways, and optimized for readability, SEO, and journalistic integrity while preserving the original HTML structure: --- As the crypto market continues to evolve, investor preferences remain primarily anchored around Bitcoin and Ethereum, with questions surrounding the next wave of promising digital assets. Recent insights from Coinbase Asset Management highlight the current sentiment and potential candidates vying for a top position in the rapidly expanding blockchain ecosystem. From institutional interest to network development, the race is on to identify the next asset that could join the ranks of dominant cryptocurrencies like Bitcoin and Ethereum. Investors predominantly view Bitcoin and Ethereum as the primary crypto assets for portfolio inclusion. Solana is seen as a tentative third choice, with XRP potentially vying for the next spot pending network growth. Ripple’s XRP is making strides, but market con...