State Hackers Drive Onchain Malware Surge, Linked to North Korea and Iran
State-sponsored hackers are increasingly using public blockchains to store malware instructions and infrastructure information, according to a Chainalysis report. The number of such occurrences rose by 420% over the past 12 months, with state-linked actors accounting for roughly two-thirds of new activity each quarter.
The analytics firm identified North Korea- and Iran-linked operators among those adopting this technique. In one notable case, Chainalysis connected previously unattributed activity on Tron, Aptos, and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
The use of public blockchains makes malware campaigns more durable, as the stored information remains accessible even if domains, servers, or code repositories are taken down. In 2025, North Korean hackers used a similar technique called EtherHiding to place crypto-stealing code in smart contracts.