
State-Sponsored Hackers Exploit Blockchains for Malware, Chainalysis Reports
Vexoda Newsroom
Analysis reveals a 420% surge in on-chain malware infrastructure usage by state-linked hackers from North Korea and Iran, leveraging public blockchains for persistent cyberattack campaigns.
A significant increase in the use of public blockchains to host malware infrastructure has been documented, with state-sponsored hacking groups increasingly employing this tactic. Analysis indicates a substantial 420% rise in instances where attackers embed instructions or operational data directly onto blockchains over the past year. This sophisticated approach aims to create more resilient and enduring cyberattack capabilities, making it harder for security forces to disrupt their operations.
Key players identified in this trend include hacking groups believed to be linked to North Korea and Iran. One North Korea-linked entity, known as UNC5342, utilized the Tron and Aptos blockchains as initial routes, with BNB Smart Chain (BSC) serving as a fallback mechanism. This multi-chain strategy directed compromised devices to encrypted server addresses and configuration data, facilitating remote access and data theft through off-chain infrastructure.
The strategy involves embedding crucial data within seemingly ordinary blockchain transactions. For instance, North Korean actors used Tron and Aptos to point towards a specific BSC transaction containing encrypted command-and-control server details. This method offers a significant advantage: even if primary servers or websites are taken offline, the blockchain record remains, ensuring the malware can continue to seek instructions and maintain its operational integrity.
Separately, suspected Iranian intelligence-linked actors have been observed embedding malware directions within Bitcoin transactions. These actors leveraged a well-known Bitcoin address, historically associated with Bitcoin creator Satoshi Nakamoto, as a fixed public point for infected devices to check for updated operational commands. This strategy allows attackers to dynamically update their command-and-control infrastructure by publishing new Bitcoin transactions, to which compromised systems automatically adapt.
The rise in malicious blockchain writes has also been correlated with advancements in artificial intelligence. Since mid-2025, a notable 440% increase in such activities has been recorded, coinciding with the emergence of powerful open-source AI models capable of generating malicious code with fewer safeguards. While a direct causal link between the AI models and the specific actors' output cannot be definitively proven, the timing suggests a potential acceleration of malware development and deployment capabilities.
This trend underscores a growing threat landscape where decentralized and immutable blockchain technology is being repurposed for illicit activities. The ability to create persistent, hard-to-disrupt malware infrastructure has significant implications for cybersecurity, potentially impacting financial institutions, government agencies, and individual users. The reliance on public ledgers for command and control makes these operations more resilient against traditional takedown methods.
Traders and cybersecurity professionals should closely monitor developments in blockchain security and the evolving tactics of state-sponsored hacking groups. Attention should be paid to unusual transaction patterns on major blockchains, particularly those involving potentially obfuscated data or links to known malicious infrastructure. The continued interplay between AI advancements and cybercrime will likely present ongoing challenges for the digital asset ecosystem.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.