State Hackers Are Turning Public Blockchains Into Malware Infrastructure

fiverr
Changelly


Blockchain dead drops, a technique that hides malware command-and-control data in public blockchain transactions, surged about 440% over the past year, according to a September 17 report from blockchain analytics firm Chainalysis.

The method hides malware command-and-control (C2) data inside public blockchain transactions, letting attackers rotate infrastructure without reinfecting victims. 

Sponsored

Crypto Prediction Markets

Phemex

18+ · Gambling involves risk. Play responsibly.

State-sponsored groups from North Korea and Iran are now leading adopters, Chainalysis says

How Blockchain Dead Drops Work

Blockchain dead drops (BDD) use public blockchain transactions or smart contracts to store malware instructions and pointers to command-and-control (C2) infrastructure.

The term “dead drop” comes from espionage, where information or supplies are left at a location for another party to retrieve without direct contact. In this case, malware checks a public blockchain for hidden instructions instead of relying solely on a conventional C2 server.

Attackers typically use two methods:

  • Transactions: They hide server addresses, malware links, or other instructions in blockchain transactions.
  • Smart contracts: They store the same kind of information in smart contracts, which can be updated as the attackers change their infrastructure.

Once the malware gets the information it needs, the attack moves off the blockchain. It may then steal passwords and cryptocurrency credentials or give attackers remote control of an infected computer.

Security researchers have seen Iranian, North Korean and russian threat actors use these techniques. Attackers are also developing new methods, including hiding a command server’s IP address inside specially crafted blockchain wallet addresses.

Blockchain Dead Drops are Surging

Hackers have used blockchains to hide malware commands since at least 2013, but the technique has expanded sharply in recent years.

A major breakthrough came in 2023, when attackers began hiding malicious code in smart contracts in a technique known as EtherHiding.

According to Chainalysis, the activity has now surged. Researchers recorded an increase from 2.06 malicious blockchain writes per day to 11.1 per day — a 440% jump in less than a year.

The rise has been linked to easier access to powerful AI tools, which have lowered the technical barrier for attackers. Researchers are now tracking blockchain-based command systems across five major blockchains and more than a dozen malware strains.

State-Backed Hackers Now Dominate

At first, almost all blockchain dead-drop activity came from cybercriminals. That began to change in mid-2024, as state-linked groups entered the picture.

Chainalysis says state-linked groups now account for roughly two-thirds of new blockchain dead drop activity each quarter and half of all activity.

Researchers say groups linked to North Korea, Iran and Russia are now expanding techniques first used by cybercriminals.

How Hackers Use Blockchain Dead Drops 

In 2025, North Korean-linked hackers used multiple blockchains to hide instructions for malware targeting cryptocurrency developers. Using several blockchains gave the operation backup routes and made it harder to disrupt. The malware ultimately targeted victims’ crypto credentials.

Iranian-linked operators hid instructions inside Bitcoin transactions. Malware retrieves and decodes the hidden data to find the attackers’ current servers, which can be changed without updating the malware itself.

Russian criminal groups are using smart contracts on Polygon to run a malware-for-hire service. One operator can manage many contracts, allowing different criminal customers to use the same underlying infrastructure.

How Security Teams Can Detect Blockchain Dead Drops 

Public blockchains are cheap to use and difficult to shut down. Chainalysis says blocking blockchain traffic isn’t a practical solution because it could disrupt legitimate crypto services while attackers could simply find another way in.

Instead, security teams can monitor blockchain transactions for signs of malicious activity. Because blockchain records are public and difficult to change, they can help investigators identify attackers and track their infrastructure.

Why This Matters

Blockchain dead drops are no longer limited to individual hacking campaigns. They are being used by hostile states and their criminals as flexible infrastructure that can be updated, reused and shared across multiple attacks.

Discover DailyCoin’s popular crypto news today:
SHIB Prints a Huge Wedge: This Setup Isn’t The Usual One
Bitcoin Reserve Bill Advances in House Committee

DailyCoin’s Vibe Check: Which way are you leaning towards after reading this article?





Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*