State-Sponsored Hackers Fuel Blockchains as Malware Infrastructure
State-linked hackers are increasingly using public blockchains to store malware instructions and infrastructure details. Chainalysis reports that about two-thirds of new quarterly activity involving these techniques is tied to state-aligned operators, while the frequency of 'dead drop' writes has surged dramatically over the past year.
The number of times attackers stored malware-related payload information on public chains rose 420% in the last 12 months. Chainalysis also highlights cases involving North Korea- and Iran-linked groups, showing how encoded blockchain data can outlast takedowns of domains, servers, or code repositories.
Chainalysis linked previously unattributed activity across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence. The firm also recorded a 440% rise in malicious blockchain writes since July 2025, coinciding with the emergence of higher-capacity open-source AI models.
Iran-linked actors are suspected to have used Bitcoin to publish encoded command-and-control routing data that infected devices can periodically check. Chainalysis says attacker-controlled wallets sent small payments to a widely known Bitcoin address with historical ties to Satoshi Nakamoto, which is used as a permanent public location for compromised devices to retrieve updated instructions.