Chainalysis Reports 420% Spike in Blockchain-Based Malware Linked to Nation-State Hackers
Threat actors tied to North Korea leveraged Tron, Aptos and BNB Chain for malware infrastructure maintenance, while operatives suspected of Iranian affiliation embedded command instructions within Bitcoin transactions.

Government-backed threat actors were responsible for approximately two-thirds of fresh activity each quarter as instances of attackers embedding malware commands or infrastructure details on public blockchains surged 420% during the preceding 12-month period, a new Chainalysis report has revealed.
The blockchain analytics firm identified operators linked to North Korea and Iran among the nation-state threat actors embracing this methodology. Among the report's key discoveries, Chainalysis linked activity that had not been previously attributed across Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a threat group with North Korean ties that is monitored by Google Threat Intelligence.
Encrypted pointers embedded within Tron and Aptos transactions guided compromised devices to an identical BSC transaction, with the Tron blockchain functioning as the primary channel and Aptos operating as a backup option, the Chainalysis report indicated. The BSC transaction housed encrypted server locations and configuration information that linked infected devices to offchain infrastructure employed for remote control and information exfiltration.
According to Chainalysis, leveraging public blockchains enhances the resilience of malware operations because the embedded information stays available even after domains, servers or code repositories are shut down. During 2025, hackers from North Korea employed a comparable method known as EtherHiding to embed cryptocurrency-stealing code within smart contracts.

AI tools accelerate malicious writes
The firm additionally documented a 440% rise in malicious blockchain writes beginning in July 2025, a timeframe when high-capacity open-source Chinese artificial intelligence models reportedly became capable of generating malicious code with minimal safeguards, according to the company.
Eric Jardine, cybercrimes research lead at Chainalysis, told Cointelegraph that they discovered a "clear point-in-time association," but could not prove that the actors publishing the malicious transactions and contracts had used the models to increase their output.
Iran-linked actors put malware directions on Bitcoin
Chainalysis additionally identified threat actors it believes are connected to Iran's Ministry of Intelligence inscribing encoded command-and-control routing data directly onto the Bitcoin blockchain.
The firm stated its determination was grounded in the malware family, decoding method, timing and server infrastructure linked with previously documented Iranian operations, instead of relying solely on the blockchain activity.
Wallets under attacker control transmitted small payments to a widely recognized Bitcoin address with historical connections to Bitcoin creator Satoshi Nakamoto, the report states. Chainalysis clarified the address had no association with the attackers and functioned as a persistent public location that compromised devices could monitor for updated instructions.
The threat actors could modify their server infrastructure by publishing another Bitcoin transaction, following which infected devices would automatically pull the new information. After the malware acquired those instructions, the operation transitioned offchain for activities that could encompass remote access, credential theft and the deployment of additional malware.