Skip to content
Back to Guavy Wire
Crypto

Malware Operators Hijack Blockchains for Command-and-Control

Share

Cyber attackers have discovered a new way to use public blockchains, and it's not for moving money. Chainalysis has identified a growing trend of threat actors storing command-and-control information for malware directly on-chain, creating what they call Blockchain Dead Drops (BDDs). This technique, also known as EtherHiding, uses the blockchain's public, persistent data layer to store malicious instructions.

The advantage of using a blockchain is that it's much harder to take offline than traditional servers or domains. Attackers can place configuration data, addresses, or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain. This makes it difficult for security teams to block or seize the infrastructure.

Chainalysis has linked different forms of this technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups. The research shows that malicious on-chain writes have risen sharply, climbing about 440% since mid-2025.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc