NewsCryptoState-Linked Hackers Drive 420% Surge in Onchain Malware Activity, Chainalysis Finds

State-Linked Hackers Drive 420% Surge in Onchain Malware Activity, Chainalysis Finds

Author: CryptoMeter io·

Key Takeaways

  • Malware-related activity stored on public blockchains rose 420% over the past 12 months, according to Chainalysis research.
  • By the second quarter of 2026, state-affiliated groups, including North Korean and Iranian operators, made up roughly two-thirds of new blockchain dead drop activity each quarter.
  • The North Korea-linked group UNC5342 distributed its infrastructure across Tron, Aptos, and BNB Smart Chain, using encrypted configuration data and server addresses so the operation did not rely on any single network.
  • Iran-linked operators embedded operational commands directly within Bitcoin transactions, exploiting the permanence of blockchain records that cannot be removed through server seizures or domain takedowns.
  • Chainalysis has identified more than 15 campaigns and threat-actor clusters using the technique, with detection and attribution through blockchain analysis, wallet relationships, and transaction histories serving as the primary defenses.
State-Linked Hackers Drive 420% Surge in Onchain Malware Activity, Chainalysis Finds

Hackers tied to North Korea and Iran are making growing use of public blockchains to support malware operations, according to new research from blockchain analytics firm Chainalysis. The company found that activity involving malware instructions or infrastructure stored on blockchains increased 420% over the past 12 months.

The findings point to an escalating cybersecurity risk for the cryptocurrency industry. The technique, known as a blockchain dead drop, takes its name from espionage tradecraft, in which material is left at a fixed spot for an operative to collect. Here, the hiding place is a public ledger: because blockchain networks are permanent and publicly readable, attackers can store instructions that infected devices retrieve later, building infrastructure that is difficult to remove or disrupt.

State Actors Expand Their Blockchain Footprint

By the second quarter of 2026, state-linked groups accounted for roughly two-thirds of new blockchain dead drop activity each quarter, Chainalysis said. North Korean and Iranian operators were identified among the groups adopting the technique.

North Korea-linked activity shows how attackers can spread infrastructure across multiple networks. Chainalysis attributed previously unattributed activity involving Tron, Aptos and BNB Smart Chain to UNC5342, a group tracked by Google Threat Intelligence. The campaign used transactions on Tron and Aptos to steer infected devices toward data stored on BNB Smart Chain, which contained encrypted configuration details and server addresses used by the malware. Spreading the operation across chains this way means it does not depend on any single network or server.

Iran-Linked Operators Embed Commands in Bitcoin

Iran-linked operators have taken a different route. Chainalysis identified activity in which operational instructions were embedded directly inside Bitcoin transactions.

The approach exploits the permanence of blockchain records. Conventional command-and-control servers can be knocked offline through server seizures or domain takedowns, but once data is written to a public blockchain it remains accessible to anyone. The technique can support malware campaigns involving credential theft, remote access and data extraction.

Chainalysis said it has so far identified more 15 campaigns and threat-actor clusters using blockchain dead drops.

The trend also presents a challenge for cryptocurrency companies and cybersecurity teams. Blocking the underlying blockchain data is rarely practical, since public networks are designed to preserve transaction information. The same permanence and openness that make blockchains resilient, in other words, are what make them useful to malicious operators. Detection and attribution therefore remain the key defenses, Chainalysis said, with analysts examining blockchain activity, wallet relationships and transaction histories to uncover infrastructure associated with malicious campaigns.