Blockchain dead drop attacks jump 420% as state-linked hackers expand

3 min read
Blockchain dead drop attacks jump 420% as state-linked hackers expand
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

Blockchain dead drop attacks — campaigns that hide malware instructions inside public-chain transactions — jumped 420% over the past 12 months, Chainalysis says. State-linked groups now generate roughly two-thirds of new activity each quarter.

State-linked hacking groups now generate roughly two-thirds of new blockchain dead drop activity each quarter, Chainalysis said, after the technique's use surged 420% over the past 12 months. Separately, the firm measured malicious blockchain writes rising from 2.06 per day before mid-2025 to 11.1 per day, a 440% increase in less than a year, coinciding with the arrival of high-capacity, open-weight Chinese AI models.

Chainalysis calls the technique a blockchain dead drop, or BDD. Attackers place malware payloads or pointers to their current command-and-control infrastructure in transaction data or smart contracts. Infected devices read the entry, then connect to the attackers' offchain systems, where credential theft, remote access or data exfiltration takes place.

North Korea spreads routes across three chains

In one North Korea-linked campaign, Chainalysis said operators placed encoded pointers on Tron and Aptos that both led infected devices to the same transaction on BNB Smart Chain. The malware checks Tron first and falls back to Aptos, while the BNB Smart Chain transaction carries encrypted configuration data and command-and-control addresses. Chainalysis said disrupting that campaign would require coordinated action across all three chains.

Google Threat Intelligence Group independently documented the North Korea-linked group UNC5342 using a related technique since February 2025, embedding malicious code in public-chain smart contracts during fake-job-interview campaigns targeting cryptocurrency developers.

Iranian and Russian-language groups use different chains

Chainalysis also attributed a transaction-based technique to actors it suspects are linked to Iran's Ministry of Intelligence, who sent small Bitcoin payments while encoding command-and-control routing data in the transactions for malware to retrieve. The firm said the Iran assessment rests on the malware family, decoding logic, timing and infrastructure rather than the blockchain activity alone.

Russian-language criminal groups, meanwhile, used Polygon smart contracts to store and update infrastructure locations for malware-as-a-service customers. Chainalysis said those actors are not necessarily state-sponsored and classified them as Russian-language based on linguistic analysis and external reporting.

A persistence problem, not a bigger payload

The blockchain records do not make malware more destructive, but they remove the central server that defenders would normally seize or take offline. As long as the underlying chain stays operational, the stored code or pointer remains available. Access routes can still be pressured: Google said centralized API providers used by UNC5342 acted quickly when its researchers contacted them, although several other platforms stayed unresponsive.

Cybercriminals accounted for nearly all blockchain dead-drop activity through early 2024. By the second quarter of 2026, state-linked groups generated roughly two-thirds of new activity each quarter and represented half of all activity Chainalysis tracks.

Source: The Defiant

Trading involves risk.

Most traded markets

XAU / USD
+1.11% 4,389.86
BRENT
-0.18% 104.751
BTC / USD
+5.41% 80,844.9
EUR / USD
+0.04% 1.14798
USTEC
+0.23% 29,490.44
GOOG
+1.17% 346.54
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.