BTC $76,537.05 +1.56%
ETH $2,459.04 +3.62%
BNB $728.19 +2.55%
XRP $1.30 +3.72%
SOL $101.44 +5.19%
TRX $0.3337 -0.42%
DOGE $0.0817 +4.08%
ADA $0.2022 +5.63%
BCH $232.01 +8.34%
LINK $11.35 +6.45%
HYPE $82.56 +5.60%
AAVE $128.54 +13.07%
SUI $0.7329 +7.96%
XLM $0.1862 +7.54%
ZEC $1,484.46 +19.05%
AAPL $336.17 +0.77%
AMZN $251.67 +1.50%
GOOGL $345.51 +0.11%
MSFT $496.08 +0.44%
META $677.49 +0.26%
NVDA $219.49 +1.90%
TSLA $368.34 +2.01%
SNDK $1,596.21 +4.01%
INTC $110.94 +8.62%
SPCX $155.00 +2.62%
MU $976.32 +4.60%
AMD $546.54 +4.30%
BTC $76,537.05 +1.56%
ETH $2,459.04 +3.62%
BNB $728.19 +2.55%
XRP $1.30 +3.72%
SOL $101.44 +5.19%
TRX $0.3337 -0.42%
DOGE $0.0817 +4.08%
ADA $0.2022 +5.63%
BCH $232.01 +8.34%
LINK $11.35 +6.45%
HYPE $82.56 +5.60%
AAVE $128.54 +13.07%
SUI $0.7329 +7.96%
XLM $0.1862 +7.54%
ZEC $1,484.46 +19.05%
AAPL $336.17 +0.77%
AMZN $251.67 +1.50%
GOOGL $345.51 +0.11%
MSFT $496.08 +0.44%
META $677.49 +0.26%
NVDA $219.49 +1.90%
TSLA $368.34 +2.01%
SNDK $1,596.21 +4.01%
INTC $110.94 +8.62%
SPCX $155.00 +2.62%
MU $976.32 +4.60%
AMD $546.54 +4.30%
first_img

Chainalysis: North Korea and Iran hackers drive a 420% surge in on-chain malware writing volume

2026-09-17 20:16:47

According to Cointelegraph, a report by Chainalysis shows that in the past 12 months, the number of times attackers stored malware instructions or infrastructure information on public blockchains has surged by 420%, with state-sponsored hackers contributing about two-thirds of the new activity each quarter. Chainalysis linked previously unattributed activities on Tron, Aptos, and BNB Smart Chain to the North Korean-backed organization UNC5342.

The report points out that the encoded pointers in Tron and Aptos transactions direct infected devices to the same BSC transaction, which contains encrypted server addresses and configuration data used to connect to remote access and data theft infrastructure. Information on public blockchains remains accessible even after domain names, servers, or code repositories are shut down, enhancing the persistence of malware activities. In 2025, North Korean hackers used similar technology called EtherHiding to implant coin theft code into smart contracts.

Additionally, since July 2025, the volume of malicious blockchain writes has increased by 440%, when high-capacity open-source Chinese AI models began to have the ability to generate malicious code. Eric Jardine, head of cybercrime research at Chainalysis, stated that a clear temporal correlation was found, but it could not be proven that the attackers used these models.

Chainalysis also identified threat actors suspected of being linked to the Iranian Ministry of Intelligence, writing encoded command and control routing data into the Bitcoin blockchain and sending small payments to well-known addresses historically associated with Satoshi Nakamoto, which are unrelated to the attackers and serve only as a permanent public location for infected devices to receive update instructions.

app_icon
ChainCatcher Building the Web3 world with innovations.