State hackers drive 420% surge in onchain malware, Chainalysis finds
State-linked hackers made up about two-thirds of new blockchain-based malware activity each quarter, while public-blockchain “dead drop” payload writes rose 420% in the past year. Chainalysis linked this trend to North Korea- and Iran-related operators. One case tied previously unattributed activity across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group. In that campaign, Tron and Aptos transactions contained encoded pointers that led infected systems to a BSC transaction with encrypted server addresses and configuration data for remote access and data theft. Using public blockchains makes campaigns harder to disrupt because the instructions persist even if domains or servers are taken down. Chainalysis also reported a 440% jump in malicious blockchain writes since July 2025, and said AI tools may be helping increase output. It also found suspected Iran-linked actors writing command-and-control data onto Bitcoin, using transactions as durable public checkpoints for malware to fetch updated directions.
