Malware Operators Use Blockchains as 'Dead Drops' for Command-and-Control Info
Malware operators have found a new way to store instructions on public blockchains, a technique called 'Blockchain Dead Drops' (BDDs) by Chainalysis. This method involves storing command-and-control information for malware directly on-chain, using the blockchain's public and persistent data layer.
The idea is that traditional malware relies on servers or domains to tell infected machines what to do next. However, security teams can block these domains or seize servers, disrupting the infrastructure. A public blockchain is harder to take offline, making it an attractive choice for attackers.
Chainalysis describes a wider technique as 'EtherHiding', which involves using the network as a highly resilient public bulletin board. Once information is written on-chain, defenders cannot simply delete it. This makes BDDs appealing for command-and-control infrastructure, as attackers can change the data their malware reads without relying on conventional web servers.
The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups. Chainalysis notes that malicious on-chain writes have risen about 440% since mid-2025.