Crypto News

Chainalysis links North Korea and Iran to 420% rise in blockchain malware activity

Chainalysis links North Korea and Iran to 420% rise in blockchain malware activity

Blockchain malware activity rose 420% in a year, Chainalysis says

Attackers stored malware instructions and infrastructure details on public blockchains far more often over the past year, according to a report from crypto analytics firm Chainalysis. The number of these writes rose 420% over 12 months, the report says.

Chainalysis says state-linked hackers made up roughly two-thirds of new activity in each quarter. It identified operators linked to North Korea and Iran among the state actors using the method. A blockchain is a public digital record that anyone can read and that keeps its history.

Key numbers from the report

  • Malware-related writes on public blockchains rose 420% over the past 12 months, according to Chainalysis.
  • State-linked actors accounted for about two-thirds of new activity each quarter.
  • Malicious blockchain writes rose 440% since July 2025, the report says.
  • Chainalysis connected previously unattributed activity across Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
  • The firm also suspects threat actors linked to Iran's Ministry of Intelligence wrote encoded control data onto the Bitcoin blockchain.

How the North Korea-linked operation used three chains

Chainalysis said encoded pointers in Tron and Aptos transactions directed infected devices to the same transaction on BNB Smart Chain. Tron served as the first route and Aptos as a fallback, according to the report. That BNB Smart Chain transaction held encrypted server addresses and configuration data, which connected compromised devices to offchain infrastructure used for remote access and data theft.

Chainalysis said storing this information on public blockchains makes malware campaigns last longer, because the data stays reachable after domains, servers or code repositories are taken down. The report notes that in 2025 North Korean hackers used a similar method called EtherHiding to place crypto-stealing code inside smart contracts.

Bitcoin used as a public drop for suspected Iran-linked activity

Chainalysis said it suspects threat actors linked to Iran's Ministry of Intelligence wrote encoded command-and-control routing data onto the Bitcoin blockchain. The company said its assessment was based on the malware family, the decoding method, the timing and the server infrastructure associated with previously reported Iranian operations, rather than on the blockchain activity alone.

According to the report, attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to Bitcoin creator Satoshi Nakamoto. Chainalysis said the address had no connection to the attackers and served as a permanent public location where infected devices could check for updated directions.

The report says attackers could change their server infrastructure by publishing another Bitcoin transaction, after which infected devices would automatically retrieve the new information. Once the malware had those instructions, the operation moved offchain for activities that could include remote access, credential theft and the delivery of additional malware.

An AI link Chainalysis could not prove

The report records a 440% increase in malicious blockchain writes since July 2025, when Chainalysis said high-capacity open-source Chinese artificial intelligence models became capable of producing malicious code with limited safeguards.

Eric Jardine, cybercrimes research lead at Chainalysis, told Cointelegraph that the team found a “clear point-in-time association,” but could not prove that the actors publishing the malicious transactions and contracts had used the models to increase their output.

What is confirmed and what is not

The 420% and 440% figures, the two-thirds share and the transaction patterns described above all come from Chainalysis, the analytics firm behind the report. Its attribution of the Iran-linked activity is presented as an assessment, based on the malware family, decoding method, timing and server infrastructure, and not only on what appeared on the blockchain.

The report does not show that the attackers used AI models to produce more malicious code. Chainalysis described an association in time, and its research lead said the link could not be proven from the data.

Why the method is hard to shut down

Public blockchains are open records that keep their data. Chainalysis says instructions written to them can remain available after the usual ways of stopping a campaign, such as taking down a domain, a server or a code repository, no longer work. The report calls these stored instructions blockchain dead drops, meaning public spots where infected devices can pick up directions.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!