
State-linked hackers from North Korea and Iran, among others, are increasingly storing malware commands and infrastructure information on public blockchains, according to a recent analysis.
According to Chainalysis, such blockchain-based malicious activity increased by 420% over the past 12 months, with state-linked hackers accounting for about two-thirds of newly detected activity each quarter. Chainalysis analyzed that operators linked to North Korea and Iran are using the technique.
In particular, activity found on Tron, Aptos and BNB Smart Chain was linked to UNC5342, a group tracked by Google Threat Intelligence as North Korea-linked. Pointers stored in Tron and Aptos transactions directed infected devices to the same BSC transaction, which contained encrypted server addresses and configuration information for connecting to off-chain infrastructure used for remote control and data theft.
Chainalysis explained that using public blockchains can improve the persistence of malware campaigns, as stored information remains accessible even if conventional domains, servers or code repositories are blocked. In 2025, North Korean hackers also used the “EtherHiding” technique to store malicious code in smart contracts and blockchain transactions.
