State-Sponsored Hackers Flood Public Blockchains with Malware Instructions
State-sponsored hackers have significantly increased their use of public blockchains to host malware instructions and infrastructure information, according to a recent Chainalysis report. The number of times attackers stored this type of data on public chains rose 420% over the past year.
North Korea and Iran-linked operators are among the state actors adopting this technique, which allows them to increase the durability of their malware campaigns. Even if domains, servers, or code repositories are taken down, the stored information remains accessible.
Chainalysis identified a North Korea-linked group tracked by Google Threat Intelligence as behind previously unattributed activity on Tron, Aptos, and BNB Smart Chain (BSC). The firm found that infected devices were directed to a BSC transaction containing encrypted server addresses and configuration data used for remote access and data theft.
The company also recorded a 440% increase in malicious blockchain writes since July 2025, when high-capacity open-source Chinese AI models became capable of producing malicious code with limited safeguards. While Chainalysis couldn't prove that the actors publishing these transactions had used the models to increase their output, Eric Jardine noted a 'clear point-in-time association.'