Malware Operators Hijack Blockchains for Command-and-Control
Cyber attackers have discovered a new way to use public blockchains, and it's not for moving money. Chainalysis has identified a growing trend of threat actors storing command-and-control information for malware directly on-chain, creating what they call Blockchain Dead Drops (BDDs). This technique, also known as EtherHiding, uses the blockchain's public, persistent data layer to store malicious instructions.
The advantage of using a blockchain is that it's much harder to take offline than traditional servers or domains. Attackers can place configuration data, addresses, or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain. This makes it difficult for security teams to block or seize the infrastructure.
Chainalysis has linked different forms of this technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups. The research shows that malicious on-chain writes have risen sharply, climbing about 440% since mid-2025.