Crypto news report · source clearly identified
Blockchain Malware Activity Surges 440% as AI Eases Use by State-Linked Hackers
Public blockchains are increasingly used for malware command-and-control, with AI tools lowering the technical barrier. North Korean and Iranian groups now account for about two‑thirds of observed blockchain dead‑drop activity, and overall malicious writes rose from 2.06 to 11.1 per day.

State‑linked hacking groups are turning public blockchains into resilient command‑and‑control layers, a shift that has driven a 440% rise in malicious blockchain writes over the past year.
Growth of blockchain‑based dead drops
Chainalysis reports that daily malicious writes on public chains increased from 2.06 to 11.1 after the emergence of high‑capacity open‑weight Chinese AI models. The firm attributes the surge to lower expertise requirements, though it does not single out any specific model.
State‑linked actors dominate
By Q2 2026, groups linked to North Korea and Iran accounted for roughly two‑thirds of newly observed blockchain dead‑drop activity, representing about half of all activity tracked by Chainalysis—up from a negligible share in early 2024.
North Korean redundancy
The UNC5342 group uses TRON and Aptos as redundant routes to BNB Smart Chain (BSC). Infected devices query TRON first, then switch to Aptos if needed, and can be redirected by posting new transactions on any of the three chains.
Iranian routing via Bitcoin
Actors tied to Iran’s Ministry of Intelligence embed command‑and‑control pointers in Bitcoin transactions sent to a well‑known address historically associated with Satoshi Nakamoto. The address itself is unrelated to the attackers and serves only as a public reference point.
AI lowers the barrier for broader adoption
Artificial‑intelligence coding tools are enabling non‑state actors to adopt the same techniques. Russian‑language criminal groups have deployed smart contracts on Polygon as command resolvers, offering them through a malware‑as‑a‑service model. A primary wallet was identified controlling multiple resolver contracts, each serving separate customers or campaign variants.
Defensive implications
The permanence of blockchain records provides a surveillance opportunity: every transaction that updates infrastructure is timestamped and publicly visible. Defenders can map operator wallets, resolver contracts, funding flows, and update histories to link campaigns.
Monitoring outbound JSON‑RPC requests to blockchain nodes offers another detection vector, while centralized API providers and RPC gateways remain potential choke points for intervention.
Economic incentives
Posting small data payloads on public chains is inexpensive, and the data remains globally accessible, allowing attackers to keep most of the compromise off‑chain while using the ledger merely as a coordination layer.
Outlook
As more malware treats public chains as persistent coordination layers, security teams will need to track activity across wallets, contracts, and multiple networks without disrupting legitimate blockchain use. The next pressure point may be RPC and API providers, whose ability to filter malicious queries could limit the resilience of these attacks.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- September 18, 2026, 10:50 AM
- Original headline
- Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers