Attackers Abuse Blockchains as 'Dead Drops' for Malware
Cyber attackers have found a new way to store malware instructions on public blockchains, according to Chainalysis. This technique is called Blockchain Dead Drops (BDDs), and it involves storing command-and-control information for malware directly on-chain.
The blockchain itself is not compromised; attackers are using its public, persistent data layer as a highly resilient bulletin board. Once information is written on-chain, defenders cannot simply delete it, making BDDs attractive for command-and-control infrastructure.
Chainalysis describes the wider technique as EtherHiding, which involves using the network as a public noticeboard instead of compromising a blockchain protocol. The research links different forms of this technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.
The security problem arises when malware treats the permanent data layer as infrastructure, creating a frustrating problem for defenders. Malicious software can still be detected and removed from infected devices, but the data it relies on may remain publicly accessible indefinitely.