North Korea- and Iran-linked hacking groups were behind most of a sharp increase this year in malware activity using public blockchains, according to a new report from blockchain analytics firm Chainalysis.

The company said onchain malware activity rose 420% this year, with state-linked actors accounting for roughly two-thirds of new cases in which attackers stored malware instructions or infrastructure data on public networks. Chainalysis argues that putting such data on blockchains can make malicious campaigns more resilient because the information may remain available even after traditional hosting points are removed.

State-linked actors dominated new cases

Chainalysis said the majority of the increase came from groups tied to North Korea and Iran. The report focused on cases where attackers used blockchains not just for moving funds, but as a place to publish instructions or supporting infrastructure for malware operations.

That shift matters because public chains are difficult to alter or remove. According to Chainalysis, information embedded or referenced onchain can remain reachable even after domains, servers or code repositories tied to a campaign have been taken down, complicating disruption efforts.

UNC5342 tied to activity across multiple chains

The firm also said it linked previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a group it described as North Korea-linked.

That attribution expands the picture of how these operations are spread across several networks rather than concentrated on a single chain. The report did not present the activity as entirely new, but as newly connected to a specific threat actor.

Earlier tactics offer a point of comparison

Chainalysis pointed to a related method used in 2025, when North Korean hackers employed a technique known as EtherHiding to place crypto-stealing code in smart contracts.

The comparison suggests continuity in how North Korea-linked operators use blockchain-based infrastructure to keep malicious code or instructions available for longer periods than conventional web hosting might allow.

Separate report describes hiring-front infiltration efforts

In a separate development cited by NBC, North Korea is reportedly using remote workers from third countries, including Iran and Lebanon, to help pass job interviews for roles at US companies. After the hiring process, those positions are then allegedly taken over by North Korean operatives.

NBC said the objective is to infiltrate US firms and raise money for North Korea’s weapons programs. The report sits alongside the Chainalysis findings as another example of how the country is said to blend cyber operations with foreign intermediaries.

What is confirmed so far

The confirmed findings in the source material are limited but notable: Chainalysis reported a 420% yearly jump in onchain malware activity, said state-linked hackers drove about two-thirds of new cases, and attributed previously unattributed multi-chain activity to the North Korea-linked group UNC5342.

The next concrete step will likely be further attribution and disruption work by security firms and investigators. For now, the report’s central point is that public blockchain infrastructure can give malware campaigns a degree of persistence that outlasts ordinary takedowns.

Source: cointelegraph.com