Blockchain dead drop attacks — campaigns that hide malware instructions inside public-chain transactions — jumped 420% over the past 12 months, Chainalysis says. State-linked groups now generate roughly two-thirds of new activity each quarter.
State-linked hacking groups now generate roughly two-thirds of new blockchain dead drop activity each quarter, Chainalysis said, after the technique's use surged 420% over the past 12 months. Separately, the firm measured malicious blockchain writes rising from 2.06 per day before mid-2025 to 11.1 per day, a 440% increase in less than a year, coinciding with the arrival of high-capacity, open-weight Chinese AI models.
Chainalysis calls the technique a blockchain dead drop, or BDD. Attackers place malware payloads or pointers to their current command-and-control infrastructure in transaction data or smart contracts. Infected devices read the entry, then connect to the attackers' offchain systems, where credential theft, remote access or data exfiltration takes place.
North Korea spreads routes across three chains
In one North Korea-linked campaign, Chainalysis said operators placed encoded pointers on Tron and Aptos that both led infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and falls back to Aptos, while the BNB Smart Chain transaction carries encrypted configuration data and command-and-control addresses. Chainalysis said disrupting that campaign would require coordinated action across all three chains.
Google Threat Intelligence Group independently documented the North Korea-linked group UNC5342 using a related technique since February 2025, embedding malicious code in public-chain smart contracts during fake-job-interview campaigns targeting cryptocurrency developers.
Iranian and Russian-language groups use different chains
Chainalysis also attributed a transaction-based technique to actors it suspects are linked to Iran's Ministry of Intelligence, who sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said the Iran assessment rests on the malware family, decoding logic, timing and infrastructure rather than the blockchain activity alone.
Russian-language criminal groups, meanwhile, used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers. Chainalysis said those actors are not necessarily state-sponsored and classified them as Russian-language based on linguistic analysis and external reporting.
A persistence problem, not a bigger payload
The blockchain records do not make malware more destructive, but they remove the central server that defenders would normally seize or take offline. As long as the underlying chain stays operational, the stored code or pointer remains available. Access routes can still be pressured: Google said centralized API providers used by UNC5342 acted quickly when its researchers contacted them, although several other platforms stayed unresponsive.
Cybercriminals accounted for nearly all blockchain dead-drop activity through early 2024. By the second quarter of 2026, state-linked groups generated roughly two-thirds of new activity each quarter and represented half of all activity Chainalysis tracks.
Source: The Defiant
Trading involves risk.