Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add preferred source
According to Chainalysis‘ latest cyber threat report, blockchain dead drop (BDD) techniques used by state-linked hacking groups are surging. North Korea-linked group UNC5342 distributed malware to cryptocurrency developers through fake job interviews, leveraging Tron, Aptos, and BNB Smart Chain across multiple pathways. An Iran-linked group was observed using the Bitcoin blockchain as a command channel. Malicious payload recordings on public blockchains rose 420% over the past 12 months, and 440% since July 2025. The timing coincides with the emergence of new AI models, though causality remains unconfirmed. Approximately two-thirds of new BDD activity is attributed to state-linked groups.
Key Elements

State-linked hacking groups are increasingly using public blockchains as malware distribution channels through a technique known as “blockchain dead drop” (BDD). A North Korea-linked group has been confirmed to target job-seeking cryptocurrency developers with fake interview offers to induce malware installation.
According to the latest cyber threat report released by blockchain analytics firm Chainalysis on the 18th, BDD activity—where attackers record malware commands or server access information on public blockchains—is spreading rapidly. Over the past 12 months, the number of malicious payload recordings on public blockchains increased 420% year-over-year.
The core danger of BDD lies in its near-impossibility to block. Traditional hacking methods could be disrupted by shutting down servers or domains, but information recorded on public blockchains cannot be arbitrarily deleted or halted by any single entity. Infected devices can access the blockchain at any time to receive new commands and resume attacks.
North Korean Group’s Multi-Chain Attack Pathways
The Google Threat Intelligence Group (GTIG) has been tracking a North Korea-linked group designated “UNC5342” since February 2025. The group targeted job seekers in the cryptocurrency sector, luring them with fake job interviews to download malware. Infected devices were designed to continuously read commands recorded on the blockchain and connect to hacker-controlled servers.
Chainalysis successfully linked previously unattributed BDD activity to UNC5342 through on-chain analysis. The group is characterized by distributing its attack pathways across multiple blockchains, including Tron (TRON), Aptos, and BNB Smart Chain (BSC).
Infected devices were designed to first check for information on Tron, then fall back to Aptos if that pathway failed. Ultimately, encrypted malware commands were routed through BSC. BSC transactions contained encrypted server addresses and configuration data, which connected infected devices to off-chain infrastructure for remote access and data exfiltration.
This multi-chain structure significantly expands the monitoring scope required of security response teams. Tracking a single chain or single contract address is insufficient to counter attackers who link multiple networks to enhance reliability.
Iran-Linked Group Uses Bitcoin as Command Channel
Beyond North Korea, BDD usage by an Iran-linked group has also been confirmed. Chainalysis detected evidence that attackers suspected of ties to Iran’s Ministry of Intelligence recorded encrypted command-and-control routing data on the Bitcoin blockchain.
This assessment was based on a combination of indicators including malware family, decoding methods, timing patterns, and server infrastructure associated with previous Iranian operations. The attacker-controlled wallet sent small amounts to a Bitcoin address known for its historical association with Satoshi Nakamoto.
That address has been confirmed to have no direct connection to the attackers. It was used as a permanent public location that infected devices could periodically check. Attackers can issue new Bitcoin transactions to change server infrastructure, and once malware receives new commands, it switches back off-chain to perform remote access, credential theft, and delivery of additional malware.
Using long-established Bitcoin addresses makes defensive blocking far more difficult. Even if obvious infrastructure is blocked, the on-chain location remains publicly accessible and continues to function as a trusted signal for infected devices.
AI Proliferation Lowers Barriers to Entry
The expansion of BDD usage is also attributed to advances in artificial intelligence (AI) technology. Chainalysis reported that malicious blockchain recordings increased 440% since July 2025. This period coincides with the emergence of high-performance Chinese open-weight large language models (LLMs) that do not restrict malware generation.
In fact, the average daily number of malicious blockchain recordings tracked by Chainalysis rose more than fivefold, from 2.06 per day before the emergence of these AI models to 11.1 per day afterward.
However, causality has not yet been established. Eric Jardine, Chainalysis’ cybercrime research lead, told Cointelegraph that while a “clear temporal correlation” was found, it cannot be definitively proven that the actors creating malicious transactions and contracts actually used these AI models to increase output.
“The data shows timing alignment, but causality remains unconfirmed,” he said. “We should not assert ‘AI usage’ in every individual case.” He added that the findings should be interpreted as an early warning that automated code-generation tools could lower the cost of blockchain-based malware creation and distribution.
State-Linked Groups Lead the Trend
As of Q2 2026, approximately two-thirds of new BDD activity is attributed to state-linked groups. Beyond North Korea and Iran, malware-as-a-service (MaaS) offerings selling or subscription-based BDD toolkits have also emerged in the Russian-speaking cybercrime ecosystem.
Kwon Jun-hyuk, head of Chainalysis Korea, said: “While blockchain exploitation by state-linked groups such as North Korea is becoming more sophisticated, the on-chain records left by attackers can actually serve as critical clues for tracking them. Leveraging blockchain intelligence to trace these footprints and identify attackers and related infrastructure will become increasingly important in responding to new cyber threats.”
Security industry experts argue that response strategies must also evolve. Traditional approaches relying on domain or server blocking have limitations; the industry must shift toward tracking behavioral patterns of payload recordings and encrypted routing mechanisms. In particular, cross-chain response capabilities that correlate and analyze encrypted command flows across multiple chains are expected to become critical.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com
