Friday, September 18, 2026

Latest Posts

Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers

State-linked hackers are increasingly using public blockchains to keep malware connected to infrastructure that traditional takedowns cannot easily disable.

Groups tied to North Korea and Iran accounted for roughly two-thirds of newly observed blockchain-dead-drop activity each quarter by the second quarter of 2026, Chainalysis said. State-linked operators now represent about half of all activity the analytics firm tracks, up from a negligible share in early 2024.

The technique, known as a blockchain dead drop, stores malware instructions, command-and-control addresses or pointers inside transactions and smart contracts. Compromised devices can repeatedly query those public records for updated instructions, letting attackers change servers without reinfecting victims.

Chainalysis said malicious blockchain writes rose from 2.06 a day to 11.1 after the emergence of high-capacity open-weight Chinese artificial-intelligence models, a 440% increase in less than a year.

The firm said those models lowered the expertise required to build the infrastructure, though its measurement does not identify a single model or establish that AI alone caused the increase.

Related Reading

Ethereum smart contracts quietly push javascript malware targeting developers

The shift adds another security challenge for crypto companies, developers and enterprises that increasingly rely on public chains for legitimate applications. Blocking access to an entire network would also disrupt wallets, decentralized-finance platforms and other services using the same infrastructure.

North Korea adds cross-chain redundancy

North Korean-linked operators are already showing how blockchain infrastructure can make a malware campaign more resilient after defenders identify its components.

Read More:  Strategy and Robinhood lead $4.5B GRNY ETF holdings

Chainalysis connected the threat group UNC5342 to a previously unattributed setup that uses TRON and Aptos as redundant routes into BNB Smart Chain. Encoded pointers on the first two networks direct infected devices toward malware instructions stored on BSC. The malware queries TRON first and switches to Aptos if that route fails.

Attackers can rotate their off-chain infrastructure by posting another transaction, after which previously infected machines automatically retrieve the updated location. Chainalysis said disrupting the operation would require action across all three chains at the same time.

Google Threat Intelligence began tracking UNC5342 in February 2025, when it used blockchain-based malware delivery in fake-job campaigns aimed at cryptocurrency and technology developers. The group used smart contracts to help deliver credential-stealing malware targeting browser data, passwords, and crypto wallets.