Malware Commands on Blockchain Surge 420 Percent

Malicious payload recordings on public blockchains rose 420% in the last year. North Korean hackers use fake job interviews to infect crypto developers.
Malicious payload recordings on public blockchains increased by 420% year-over-year. This surge marks a major shift in how state-linked actors distribute malware. The technique is known as the blockchain dead drop.
North Korea-linked group UNC5342 targets job-seeking cryptocurrency developers. They use fake interview offers to induce malware installation. Infected devices then read commands directly from public ledgers.
Multi-Chain Attack Pathways Expand
The group distributes attack pathways across Tron, Aptos, and BNB Smart Chain. Infected devices check Tron first for new instructions. If that pathway fails, they switch to Aptos.
Encrypted commands are ultimately routed through BSC. These transactions contain encrypted server addresses. This structure forces security teams to monitor multiple networks simultaneously.
Bitcoin Serves As Command Channel
An Iran-linked group also uses blockchain dead drops. Attackers recorded encrypted routing data on the Bitcoin blockchain. They used a wallet associated with Satoshi Nakamoto as a beacon.
This address has no direct connection to the attackers. It serves as a permanent public location for infected devices. Attackers issue new Bitcoin transactions to change server infrastructure.
AI Lowers Barriers For Attackers
Malicious blockchain recordings increased 440% since July 2025. This period coincides with the rise of high-performance AI tools. The technology lowers the entry barrier for non-state actors.
Chainalysis reported these figures in its latest threat assessment. The firm linked the activity to specific national intelligence services. Traditional blocking methods fail against immutable ledger records.






