Attackers are increasingly using public blockchains to store operational data for malware, and Chainalysis says the trend has accelerated sharply over the past year. In a new report, the blockchain analytics firm said malicious onchain writes climbed 420% in the last 12 months, with state-linked hackers responsible for roughly two-thirds of new activity in each quarter.
The report describes a shift in how some campaigns keep their command systems reachable. Instead of relying only on domains or servers that can be seized or shut down, operators are placing instructions and infrastructure details on public networks where the data remains available.
State-linked groups dominate recent growth
According to Chainalysis, the largest share of newly observed activity came from state-linked actors. The firm said operators tied to North Korea and suspected actors linked to Iran were among the groups using blockchains to support malware operations.
Chainalysis also said malicious blockchain writes have risen 440% since July 2025. It linked that increase to the period when high-capacity open-source Chinese AI models became capable of generating malicious code while operating with limited safeguards, though the report presents this as part of the broader backdrop to the surge.
North Korea-linked activity used multiple chains
Chainalysis said North Korea-linked operators used Tron, Aptos and BNB Chain to maintain malware infrastructure. In the activity described by the firm, encoded pointers placed in Tron and Aptos transactions directed infected devices toward the same BNB Chain transaction.
The report said Tron acted as the primary route, while Aptos served as a fallback. The BNB Chain transaction then held encrypted server addresses and configuration data, which allowed compromised devices to connect to offchain infrastructure used for remote access and data theft.
Suspected Iran-linked actors hid directions in Bitcoin
The report also described a separate method attributed to suspected Iran-linked actors. In those cases, attackers wrote encoded command-and-control routing data onto the Bitcoin blockchain.
Chainalysis said attacker-controlled wallets sent small payments to a well-known Bitcoin address associated with Bitcoin’s creator. The address itself was not connected to the attackers, but the firm said it functioned as a permanent public reference point that infected devices could monitor for updated instructions. Once new directions were published, the devices would retrieve the next-stage information offchain, enabling remote access, credential theft and delivery of additional malware.
Why public blockchains appeal to attackers
Chainalysis said the use of blockchains can make malware campaigns more resilient because information stored there remains accessible even if websites, code repositories or servers are removed. That durability reduces reliance on infrastructure that defenders can more easily disrupt.
The report pointed to a similar approach used by North Korean hackers in 2025, when crypto-stealing code was placed in smart contracts in a technique known as EtherHiding. The newly documented cases suggest that onchain infrastructure is being used not just to host code, but also to preserve routing details and configuration data needed to keep infections operational.
For now, the confirmed development is the rise in malicious writes and the involvement of state-linked actors identified by Chainalysis. The report frames the activity as an expanding use of public blockchain networks for persistence rather than a replacement for offchain malware infrastructure.
Source: cointelegraph.com