Key facts
- State-linked hackers drove a 420% surge in on-chain malware activity over the past 12 months.
State-linked hackers have significantly increased their use of public blockchains to store malware instructions, with on-chain malware activity surging 420% in the past year, according to Chainalysis. North Korea and Iran-linked actors are among those employing this tactic, using blockchains like Bitcoin, Tron, Aptos, and BNB Chain to maintain their malicious infrastructure.
The increasing use of public blockchains by state-sponsored hackers to host malware infrastructure poses a significant threat to cybersecurity and digital asset security, as it makes malicious campaigns more resilient and harder to disrupt. The involvement of AI models in generating malicious code further exacerbates this risk.
State-linked hackers have significantly ramped up their use of public blockchains to store malware instructions and infrastructure information, leading to a 420% surge in on-chain malware activity over the past 12 months, according to a report by Chainalysis. The analytics firm identified state actors linked to North Korea and Iran as key adopters of this technique.
Chainalysis connected previously unattributed activity on Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-linked group. These actors used encoded pointers in Tron and Aptos transactions to direct infected devices to a specific BNB Smart Chain transaction. This transaction contained encrypted server addresses and configuration data, enabling remote access and data theft from compromised devices. The use of public blockchains enhances malware campaign durability, as the stored information remains accessible even if domains or servers are taken down. North Korean hackers previously employed a similar method called EtherHiding in 2025 to embed crypto-stealing code in smart contracts.
The report also noted a 440% increase in malicious blockchain writes since July 2025, coinciding with the availability of high-capacity open-source Chinese AI models capable of producing malicious code with fewer safeguards. Eric Jardine, cybercrimes research lead at Chainalysis, stated that while a clear association was found, direct proof of AI models increasing output by these actors could not be established.
Furthermore, Chainalysis suspects actors linked to Iran's Ministry of Intelligence have embedded encoded command-and-control routing data onto the Bitcoin blockchain. This assessment is based on the malware family, decoding methods, timing, and server infrastructure associated with past Iranian operations. Attackers sent small payments to a Bitcoin address with historical ties to Satoshi Nakamoto, using it as a permanent public location for infected devices to retrieve updated directions. This allowed attackers to change their server infrastructure by publishing new Bitcoin transactions, enabling off-chain activities such as remote access and credential theft.