Chainalysis Finds 420% Surge in Onchain Malware From State Hackers
Security

Chainalysis Finds 420% Surge in Onchain Malware From State Hackers

September 17, 20264 min read

Chainalysis has recorded a sharp rise in a technique where state-backed hackers hide malware instructions directly on public blockchains. Such entries jumped 420% over the past year, with state-linked groups behind roughly two-thirds of new activity each quarter. Earlier campaigns almost always relied on ordinary servers and domains, so the scale of the shift toward public blockchains surprised even seasoned researchers.

What exactly did Chainalysis find?

The firm's analysts linked previously unattributed activity across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence. Encoded pointers embedded in Tron and Aptos transactions direct infected devices to the same BNB Smart Chain transaction.

Tron acts as the primary route, with Aptos serving as a fallback. The BNB Smart Chain transaction itself holds encrypted server addresses and configuration data that connect infected devices to offchain infrastructure used for remote access and data theft.

Short version: Hackers write their server addresses straight into a public blockchain, so blocking a domain or hosting provider no longer stops infected devices from finding new infrastructure.

How does this technique work in practice?

Security researchers call this a dead drop resolver. Instead of hardcoding a command server's address inside the malware itself, attackers publish it on a blockchain. That delivers several advantages at once.

  • Durability: a blockchain entry cannot be deleted or blocked the way an ordinary domain or server can.
  • An infected device simply checks a known address or transaction to fetch current instructions.
  • If old infrastructure gets discovered and shut down, attackers just publish a new transaction, and every infected device picks up the updated data automatically.
  • In 2025, North Korean hackers used a related technique called EtherHiding, placing malicious code directly inside smart contracts.
  • No central authority can retroactively delete a transaction, and thousands of independent network nodes keep an identical copy of the full history.

The term dead drop itself comes from Cold War-era spycraft, where it described a hidden physical location where agents left information for each other without ever meeting in person. In the digital version, a blockchain entry plays the same role, one any infected device anywhere in the world can check.

That is why traditional countermeasures, such as a registrar blocking a domain or police seizing a server, simply do not work against an entry written to a blockchain.

Chainalysis report at a glance
Growth in onchain malware entries, past year+420%
Share of state actors in new activity~2/3 per quarter
Growth in malicious writes since July 2025+440%
Networks used by UNC5342Tron, Aptos, BNB Smart Chain

Who is behind these attacks?

UNC5342 is Google Threat Intelligence's label for one North Korean cluster within a broader network of state hacking groups. For years these groups have funneled stolen crypto toward North Korea's missile and nuclear programs, and cybersecurity analysts have repeatedly documented that stolen assets covered a substantial share of those budgets.

Iran, for its part, appears to use similar techniques mainly to get around international sanctions rather than to steal funds outright. A hidden network of command servers on the Bitcoin blockchain lets operators maintain intelligence infrastructure without depending on traditional hosting, which is far easier to trace and take down.

For researchers, the shift toward public blockchains itself matters as much as the growth figures. State hackers used to rely mainly on compromised servers or cloud services that could be traced back through a provider. Moving command infrastructure onto a blockchain removes that dependency almost entirely.

What do Bitcoin and AI have to do with it?

Chainalysis found a separate technique used by a group it suspects is tied to Iran's Ministry of Intelligence. These attackers write commands for their malware directly into Bitcoin transactions. Attacker-controlled wallets sent small payments to a well-known address with historical ties to Bitcoin creator Satoshi Nakamoto.

Chainalysis stresses that the address itself has no connection to the attackers. It simply serves as a permanent public reference point that infected devices check regularly for new directions. When the hackers need to swap servers, they publish another Bitcoin transaction, and devices pick up the updated data automatically.

The firm also logged a 440% jump in malicious blockchain writes since July 2025, coinciding with the rise of powerful open-source Chinese AI models capable of writing malicious code with few safeguards. Chainalysis researcher Eric Jardine acknowledged a "clear point-in-time association" but said the firm cannot prove attackers are actually using those models.

What does this mean for ordinary users?

Once an infected device pulls its instructions from a blockchain, everything else happens offchain. That means remote access, credential theft, and delivery of further malware, including strains that hunt for crypto wallet passwords. The blockchain entry itself poses no danger to an ordinary holder of TRON or Bitcoin. The network just acts as a mailbox, not a theft tool in its own right.

The real risk starts earlier, at the initial infection stage through phishing or fake software. Exchanges and analytics firms already flag known attacker wallets in their monitoring systems, so stolen funds are harder to cash out unnoticed even when the command infrastructure itself is nearly impossible to shut down.

Chainalysis researchers warn that this kind of durability makes life harder for law enforcement. Taking down a domain is easy. Taking down a blockchain is not.

For crypto holders, the practical takeaway is simple. Most of these attacks start not on a blockchain but with an ordinary phishing email, a fake website, or a counterfeit wallet app. Downloading wallets and apps only from verified sources remains the most effective defense, one no dead drop technique can get around.

Comments

Your email address will not be published. Required fields are marked *

or verify by email