Increase in Malware Operations Using Public Blockchains
According to a recent report by Chainalysis, there has been an astonishing increase of 420% in the use of public blockchains for malware operations over the past year. State-sponsored hackers, primarily from North Korea and Iran, are responsible for about two-thirds of this activity. The report highlights the alarming trend of cybercriminals utilizing decentralized networks such as Tron, Aptos, and BNB Chain to shield and support their malicious infrastructure.
Connection to North Korean Hacking Group
Among the findings, Chainalysis revealed a noteworthy connection between activity on Tron, Aptos, and BNB Smart Chain (BSC), attributed to a North Korean hacking group named UNC5342, as identified by Google Threat Intelligence. Specifically, the analysis uncovered encoded commands embedded in transactions on Tron and Aptos that ultimately led infected devices to a designated BSC transaction.
The initial link was established through Tron, with Aptos serving as an alternative pathway. The BSC transaction was crucial, as it contained encrypted addresses and configuration data that allowed compromised systems remote access, facilitating data theft.
Enhancing Longevity of Malware Campaigns
Chainalysis emphasized that leveraging public blockchains significantly enhances the longevity of these malware campaigns. The information stored on these networks remains intact even if the hackers dismantle their domains or server operations. This methodology follows a similar approach called EtherHiding used by North Korean hackers in 2025, which involved embedding crypto-theft codes in smart contracts.
The report also noted a staggering 440% increase in malicious blockchain-related activities since mid-2025. This surge corresponds with the advent of advanced open-source AI tools from China, capable of generating harmful code with minimal safeguards, although the researchers were unable to definitively establish a direct correlation between these AI models and the actors conducting the malicious transactions.
Activities Linked to Iranian Hackers
Additionally, Chainalysis pinpointed activities likely linked to Iranian hackers associated with the nation’s Ministry of Intelligence. They were found to have encoded routing instructions onto the Bitcoin blockchain. Their operations were characterized not only by the specific blockchain actions but also by patterns and timing consistent with prior Iranian malware activities.
Interestingly, some of the hacker-controlled wallets were identified as having made minute transactions to a notable Bitcoin address historically tied to Bitcoin’s pseudonymous creator, Satoshi Nakamoto. Although devoid of any direct ties to the attackers, this address functions as a permanent location for infected systems to retrieve updates.
This strategy enables hackers to modify their infrastructure by broadcasting new transactions, prompting compromised devices to obtain fresh directives for actions such as credential harvesting, remote access, and deployment of additional malware.
Conclusion
In light of these developments, it is crucial for cybersecurity professionals and organizations to stay vigilant against the evolving tactics employed by state-sponsored attackers.