Public Blockchains See Surge in Malware Infrastructure, State Actors Dominate
Chainalysis has published a report revealing a significant increase in malware infrastructure on public blockchains. Over the past twelve months, there was a 420% growth in the use of public blockchains to store malware instructions or infrastructure information.
The majority of this new activity is attributed to state actors, who accounted for approximately two thirds of the new activity recorded each quarter. Among the identified groups are criminals linked to North Korea and Iran.
Chainalysis connected previously unattributed activity on Tron, Aptos, and BNB Smart Chain to the group UNC5342, tracked by Google Threat Intelligence and associated with Pyongyang. Pointers encoded in Tron and Aptos transactions directed infected devices toward a single transaction on BSC, where encrypted server addresses and configuration data were stored.
The use of public blockchains increases the durability of malware campaigns because the stored information remains accessible even when domains, servers, or code repositories are taken down. In 2025, North Korean hackers had already employed a similar technique known as EtherHiding to insert cryptocurrency-stealing code into smart contracts.