Crypto news report · source clearly identified
State‑linked hackers cause 420% rise in on‑chain malware activity
Chainalysis reports that North Korea‑ and Iran‑linked actors are responsible for roughly two‑thirds of new on‑chain malware instructions, driving a 420% increase over the past year.

State‑linked cyber groups are behind a dramatic surge in the use of public blockchains to store malware instructions, according to a recent Chainalysis report. The number of on‑chain malware writes rose 420% in the last 12 months, with state actors accounting for about two‑thirds of the new activity each quarter.
North Korean groups exploit multiple chains
Chainalysis linked previously unattributed activity on Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a group tracked as North Korea‑linked. Transactions on Tron and Aptos contained encoded pointers that directed infected devices to a single BSC transaction. That BSC transaction stored encrypted server addresses and configuration data, enabling compromised devices to connect to off‑chain infrastructure for remote access and data theft.
Iran‑linked actors use Bitcoin for command updates
The firm also identified activity it attributes to actors tied to Iran’s Ministry of Intelligence. These actors wrote encoded command‑and‑control routing data onto the Bitcoin blockchain. Small payments were sent to a well‑known Bitcoin address historically associated with Satoshi Nakamoto, which served only as a public checkpoint for infected devices to retrieve updated instructions.
AI tools accelerate malicious writes
Since July 2025, Chainalysis observed a 440% increase in malicious blockchain writes, coinciding with the emergence of high‑capacity open‑source Chinese AI models capable of generating malicious code. While a direct causal link was not proven, the timing suggests AI may be boosting the volume of on‑chain malware payloads.
Why public blockchains aid malware durability
Storing instructions on immutable ledgers makes malware campaigns more resilient. Even if domains, servers, or code repositories are taken down, the information remains accessible, allowing attackers to re‑activate or modify their operations without rebuilding infrastructure.
Source & attribution
News Source
- Publisher
- Cointelegraph
- Original date
- September 17, 2026, 12:00 PM
- Original headline
- State hackers drive 420% surge in onchain malware, Chainalysis finds