Tech.Yahoo Surge in Blockchain Dead Drops Driven by AI Models
Article Content
- •Blockchain dead drops have surged 440% since mid-2025 due to AI advancements.
- •State-linked actors from North Korea and Iran dominate this new attack vector.
- •Traditional cybersecurity measures are struggling to detect on-chain malicious activities.
Cyber threat actors have significantly increased the use of blockchain dead drops (BDDs) to hide malware instructions, with a 440% surge in activity since mid-2025, attributed to unrestricted Chinese open-source AI models. This technique allows attackers, particularly state-linked groups from North Korea and Iran, to store malicious payloads on public blockchains, making them difficult to disrupt. The average daily malicious on-chain writes rose from 2.06 to 11.1, with state actors now accounting for two-thirds of this activity. The BDD method enhances campaign durability by allowing communication with compromised devices without fear of takedowns. Notable incidents include the Glupteba campaign, which has evolved to exploit vulnerabilities in network routers and utilize Bitcoin transactions for command and control. The rise in BDDs poses a growing challenge for cybersecurity, as traditional threat intelligence platforms struggle to detect on-chain activities. Overall, the combination of AI advancements and blockchain technology has created a new landscape for cyber threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Unc5342, ClearFake and Polygon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing its evasion capabilities against detection. The Amatera infostealer has advanced features, including…