State-Backed Hackers Drive 420% Surge in Onchain Malware Activity
Nation-state hackers exploited multiple blockchains for malware infrastructure, with North Korea and Iran-linked actors leading the surge, Chainalysis reports.
Nation-state hacking groups are increasingly embedding malicious infrastructure directly into public blockchain networks, driving a 420% surge in onchain malware activity, according to new findings from blockchain analytics firm Chainalysis.
Hackers linked to North Korea were identified using Tron, Aptos and BNB Chain to sustain and coordinate malware operations, taking advantage of the decentralized and censorship-resistant nature of those networks to maintain persistent command infrastructure. The use of multiple chains suggests deliberate efforts to diversify footholds and complicate takedown efforts by authorities.
Read more Who Benefits Most From Trump's 'Big Beautiful Bill' Tax Cuts →
Separately, suspected Iran-linked actors were found embedding operational instructions directly within Bitcoin transactions, a technique that exploits the immutability of the blockchain ledger to relay commands in a way that is difficult to intercept or erase. The tactic represents an evolution in how state-sponsored groups weaponize public financial infrastructure for covert communications.
The findings highlight a growing convergence between nation-state cyber operations and decentralized technology, as adversaries seek out platforms where traditional law enforcement and platform moderation have limited reach. Blockchain's transparency, while useful for investigators like Chainalysis, does not always translate into timely disruption of active threats, particularly when actors move quickly across chains.
The sharp acceleration in onchain malware marks a significant shift in the threat landscape for both the cryptocurrency industry and national security agencies tracking state-sponsored cyber actors. Continue reading at Cointelegraph.