State Hackers Hijack Public Blockchains for Malware Infrastructure
State-sponsored hackers are increasingly using public blockchains as malware infrastructure, according to a report from blockchain analytics firm Chainalysis. This technique, known as blockchain dead drops, involves hiding malware command-and-control data in public blockchain transactions or smart contracts.
The method allows attackers to rotate their infrastructure without reinfecting victims, making it difficult for security teams to track and disrupt their operations. The activity has surged 440% over the past year, with state-linked groups now accounting for roughly two-thirds of new blockchain dead drop activity each quarter.
Chainalysis notes that the rise in blockchain dead drops is linked to easier access to powerful AI tools, which have lowered the technical barrier for attackers. Researchers are tracking blockchain-based command systems across five major blockchains and more than a dozen malware strains.