State-Sponsored Hackers Fuel 420% Surge in Onchain Malware
State-sponsored hackers have significantly increased their use of onchain malware, according to a report from Chainalysis. Over the past 12 months, there has been a 420% surge in new activity related to storing malware instructions or infrastructure information on public blockchains.
The analytics firm identified North Korea and Iran-linked operators among the state actors adopting this technique. In one instance, Chainalysis connected previously unattributed activity spanning Tron, Aptos, and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
Encoded pointers in Tron and Aptos transactions directed infected devices to the same BSC transaction. The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.