North Korea Tied to Surge in On-Chain Malware
North Korea-linked hackers are behind a significant spike in on-chain malware activity, according to research from Chainalysis. The firm reports a 420% increase in on-chain malware this year, with state-linked actors responsible for most of the jump.
The majority of new on-chain malware cases involve attackers posting malware instructions or infrastructure details, which account for about two-thirds of all cases. Chainalysis identified UNC5342, a North Korea-linked group, tying it to previously unattributed activity across multiple ecosystems, including Tron, Aptos, and BNB Smart Chain.
Public blockchains can make malicious campaigns more resilient by allowing attackers to store instructions and supporting infrastructure information on-chain, making it difficult for defenders to eliminate the malware even after off-chain components are removed.