LATEST NEWS
SELECTED FOR YOU

North Korea and Iran drive 5.2x jump in malware hidden on public blockchains

ByHannah CollymoreHannah Collymore 3 mins read
North Korea and Iran drive 5.2x jump in malware hidden on public blockchains
  • Chainalysis reported on Thursday that malware writes to public blockchains jumped 420% over the past year.
  • It attributed the climb to state hackers tied to North Korea and Iran.
  • Code stored on-chain survives the server and domain takedowns that usually stop a campaign.

Chainalysis specifically named hackers with North Korean and Iranian ties for most of the 420% surge it spotted in the number of instances where attackers wrote malware instructions or infrastructure data on public blockchains over the past year. 

The Thursday report published by the Blockchain analytics firm set off alarms at exchanges, wallet providers, and security teams, as these kinds of malicious codes exploit blockchain’s nature to persist longer than those parked on traditional servers or domains that can be taken down by seizing the site.

What is a blockchain dead drop? 

According to Chainalysis, the “blockchain dead drop” or BDD technique is a process where attackers park payloads and command-and-control pointers inside on-chain transactions and smart contracts. That way, infected machines can fetch them when it’s time to act. 

The method became popular among hackers because of how blockchain technology, by its nature, exponentially increases the viability of stored data. Campaigns die a natural death when the domain gets seized, hosting is cut off, or the code repository is removed. However, instructions stored on a public ledger persists and remains accessible through all these conditions.

Per Chainalysis, the first instance of this tactic on record goes as far back as 2013, when a Necurs botnet variant parked its C2 domains on Namecoin. In a separate 2019 case, operators of the Glupteba mining botnet used Bitcoin’s OP_RETURN field to hide data. 

The trend spread under the EtherHiding label to Ethereum-style chains in mid-2023. The first of its kind happened when ClearFake operators migrated their infostealer code to BNB Smart Chain after Cloudflare took down their servers. 

As of early 2024, ordinary cybercriminals were responsible for most of the activity. However, fast forward to the second quarter of 2026, Chainalysis is now reporting that nation-state operators are now writing roughly two of every three dead-drop on public blockchains. 

North Korean and Iranian operators are active 

Chainalysis completed the loop on an investigation by connecting a set of previously unattributed transactions across three networks to a North Korea-tied group on Google Threat Intelligence’s radar, UNC5342. 

That campaign, which routed infected devices through Tron, Aptos as a backup, and ending at the same BNB Smart Chain transaction, mirrored another instance from 2025 when North Korean hackers planted crypto-stealing code inside Ethereum-style smart contracts (EtherHiding).

Chainalysis also found links to Iran’s Ministry of Intelligence while investigating an operation that encoded C2 routing data directly on the Bitcoin blockchain. 

The Iranian method carried the unusual signature of sending tiny payments from attacker wallets to a Bitcoin address rumored to have ties to Satoshi Nakamoto. 

Open-weight AI models have aided the operations

The 440% rise in malicious dead drops since July 2025 has coincided with the most advanced open-source Chinese AI models unlocking the capacity to write A-level code. In raw terms, writes went up from about 2.06 to 11.1 a day.

Eric Jardine, Chainalysis’s cybercrimes research lead, said the firm could not confirm the actors publishing the malicious transactions had actually used the models to boost their output.

The report lands on top of a long run of North Korean crypto activity. CertiK estimated in May that DPRK-linked actors have stolen about $6.75 billion since 2016 across 263 incidents, leaning on social engineering rather than pure software exploits, as Cryptopolitan reported

Separate research presented at Black Hat this year put the reach wider still, with one investigator finding North Korean operators had infiltrated 1,640 companies across 57 countries. U.S. intelligence has said funds taken by these operations help pay for the regime’s nuclear and missile programs, a charge Pyongyang has denied.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

FAQs

What is a blockchain dead drop?

It is a technique, named by Chainalysis, in which attackers store malware payloads or command-and-control pointers inside on-chain transactions and smart contracts, so infected devices can retrieve them and the setup survives domain seizures and server takedowns.

Which blockchains did the North Korean and Iranian hackers use?

According to Chainalysis, the North Korea-linked group UNC5342 used Tron, Aptos, and BNB Smart Chain, routing devices first through Tron and falling back to Aptos, while suspected Iran-linked actors embedded C2 routing data in Bitcoin transactions, including payments to a Bitcoin address historically tied to Satoshi Nakamoto.

Why did on-chain malware activity spike over the past year?

Chainalysis recorded a 440% rise in malicious writes since July 2025, when high-capacity open-source Chinese AI models became capable of generating malicious code with limited safeguards, though the firm said it could not prove the attackers used those models to increase their output.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS