North Korea, Iran Linked to 420% Surge in Blockchain-Based Malware Activity: Chainalysis
Key Takeaways
- •Malicious use of public blockchains to store malware instructions and infrastructure data grew 420% over the past 12 months, with state-linked hackers responsible for about two-thirds of new activity each quarter.
- •Chain connected previously unattributed activity across Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence, with encoded pointers routing infected devices to a BSC transaction holding encrypted server addresses.
- •Suspected Iran-linked actors placed encoded command-and-control routing data on the Bitcoin blockchain by sending small payments to a well-known Satoshi Nakamoto-associated address, which had no connection to the attackers but served as a permanent public reference for compromised devices.
- •Storing malware data on public blockchains makes campaigns more durable because entries persist even after domains, servers or repositories are taken down, though the same openness lets researchers reconstruct and attribute on-chain footprints.
- •Chainalysis recorded a 440% jump in malicious blockchain writes since July 2025, coinciding with high-capacity open-source Chinese AI models becoming capable of producing malicious code with limited safeguards, though a causal link could not be proven.

The number of times attackers stored malware instructions or infrastructure information on public blockchains rose 420% over the past 12 months, with state-linked hackers accounting for roughly two-thirds of new activity each quarter, according to a report by blockchain analytics firm Chainalysis.
Chainalysis identified North Korea- and Iran-linked operators among the state actors adopting the technique. In one of the report's findings, the analytics firm connected previously unattributed activity spanning Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence. The "UNC" designation is used by Google researchers for clusters of malicious activity that have been grouped together but not yet formally named.
Encoded pointers embedded in Tron and Aptos transactions directed infected devices to the same BSC transaction, with Tron serving as the first route and Aptos as a fallback, Chainalysis reported. The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.
According to Chainalysis, the use of public blockchains increases the durability of malware campaigns because stored information remains accessible even after domains, servers or code repositories are taken down. The same permanence cuts both ways: because the entries sit on open ledgers, researchers can reconstruct and attribute on-chain footprints after the fact, as the report's own tracing of the multi-chain routes shows. In 2025, North Korean hackers employed a similar technique, known as EtherHiding, to place crypto-stealing code in smart contracts.
AI tools accelerate malicious writes
The firm also recorded a 440% increase in malicious blockchain writes since July 2025, when it said high-capacity open-source Chinese artificial intelligence models became capable of producing malicious code with limited safeguards.
Eric Jardine, cybercrimes research lead at Chainalysis, told Cointelegraph that researchers observed a “clear point-in-time association,” but could not prove that the actors publishing the malicious transactions and contracts had used the models to increase output.
Iran-linked actors put malware directions on Bitcoin
Chainalysis also identified threat actors it suspects are linked to Iran's Ministry of Intelligence writing encoded command-and-control routing data onto the Bitcoin blockchain.
The company said its assessment was based on the malware family, decoding method, timing and server infrastructure associated with previously reported Iranian operations, rather than the blockchain activity alone.
According to the report, attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to Bitcoin creator Satoshi Nakamoto. Chainalysis said the address had no connection to the attackers and served as a permanent public location where infected devices could check for updated directions. Bitcoin's ledger has operated continuously since its 2009 launch, giving such on-chain references a longevity that conventional hosting cannot guarantee.
The attackers could change their server infrastructure by publishing another Bitcoin transaction, after which infected devices would automatically retrieve the new information. Once the malware obtained those instructions, the operation moved offchain for activities that could include remote access, credential theft and the delivery of additional malware.