Back Finance.Biggo State hackers fuel 420% jump in blockchain malware, Chainalysis says
The volume of malware instructions and infrastructure data planted on public blockchains has surged 420 percent over the past year, with state-linked operators now responsible for roughly two of every three such payloads, according to new research from blockchain analytics firm Chainalysis.
The findings, published Thursday, point to a significant escalation in a tactic security researchers call the "blockchain dead drop," or BDD. The technique allows attackers to store malicious payloads and command-and-control routing information inside on-chain transactions and smart contracts, where the data remains accessible long after conventional hosting infrastructure has been dismantled.
North Korean and Iranian operators were singled out as the most active state actors adopting the method. In one investigation, Chainalysis connected a set of previously unattributed transactions spanning three separate networks to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
That campaign routed infected devices through Tron as the primary channel, with Aptos serving as a backup path, before terminating at the same transaction on BNB Smart Chain. The BSC transaction contained encrypted server addresses and configuration data that linked compromised machines to offchain infrastructure used for remote access and data theft, Chainalysis said.
The operation mirrored a similar approach from 2025, when North Korean hackers used a technique known as EtherHiding to plant crypto-stealing code inside smart contracts on Ethereum-style chains. The persistence of on-chain data gives such campaigns a durability advantage over malware parked on traditional servers, which can be neutralized when domains are seized or hosting accounts are terminated.
Iranian signature on Bitcoin
Chainalysis also identified threat actors believed to be connected to Iran's Ministry of Intelligence writing encoded command-and-control routing data directly onto the Bitcoin blockchain. The assessment drew on the malware family involved, decoding methods, timing, and server infrastructure tied to previously reported Iranian operations, rather than on-chain activity alone.
One unusual signature stood out: attacker-controlled wallets sent small payments to a well-known Bitcoin address with historical ties to Satoshi Nakamoto, the pseudonymous creator of Bitcoin. Chainalysis stressed the address had no connection to the attackers themselves. Instead, it functioned as a permanent public location that infected devices could check for updated instructions.
The arrangement gave operators a way to rotate their server infrastructure simply by publishing another Bitcoin transaction. Infected machines would then automatically retrieve the new routing information. Once the malware obtained those instructions, the operation shifted offchain for activities that could include remote access, credential theft, and the delivery of additional malware.
The rise of the dead drop
The first documented instance of the tactic dates to 2013, when a Necurs botnet variant parked its command-and-control domains on Namecoin. In 2019, operators of the Glupteba mining botnet used Bitcoin's OP_RETURN field to conceal data.
The technique gained broader traction in mid-2023 under the EtherHiding label, when ClearFake operators migrated their infostealer code to BNB Smart Chain after Cloudflare took down their servers. As recently as early 2024, ordinary cybercriminals accounted for most of the activity. By the second quarter of 2026, however, nation-state operators were writing approximately two-thirds of all dead-drop payloads on public blockchains, according to Chainalysis.
The raw pace of malicious writes has also accelerated. Since July 2025, the analytics firm recorded a 440 percent increase in the number of malicious blockchain writes, from 2.06 per day to 11.1 per day.
That timing coincides with the emergence of high-capacity open-source Chinese artificial intelligence models capable of producing competent malicious code with limited safeguards. Eric Jardine, cybercrimes research lead at Chainalysis, said the firm found a "clear point-in-time association" between the two trends, but could not confirm that the actors publishing the malicious transactions had actually used the models to boost their output.
Broader North Korean activity
The report adds to a growing body of evidence documenting North Korean cyber operations. CertiK estimated in May that DPRK-linked actors have stolen approximately $6.75 billion since 2016 across 263 incidents, leaning heavily on social engineering rather than pure software exploits. Separate research presented at Black Hat this year put the reach wider still, with one investigator finding North Korean operators had infiltrated 1,640 companies across 57 countries.
U.S. intelligence has said funds taken by these operations help pay for the regime's nuclear and missile programs, a charge Pyongyang has denied.
For exchanges, wallet providers, and security teams, the shift toward blockchain-based malware distribution presents a difficult challenge. Unlike traditional infrastructure, which can be seized or taken offline, data written to a public ledger persists indefinitely. The immutable nature of blockchains, long touted as a feature for legitimate applications, has become a liability in the fight against state- cybercrime.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
