Cointelegraph iconCointelegraphSep 17, 2026 ~1 min source read

State hackers drive 420% surge in onchain malware, Chainalysis finds

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions. Chainalysis identified North Korea and Iran-linked operators among the state actors adopting the technique.

State hackers drive 420% surge in onchain malware, Chainalysis finds

Share this story

Send the public story page.

Useful takeaways from this story.

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.

The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.

Chainalysis identified North Korea and Iran-linked operators among the state actors adopting the technique.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions. Chainalysis identified North Korea and Iran-linked operators among the state actors adopting the technique. In one of the report's findings, the analytics firm connected previously unattributed activity spanning Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.

How it works

  • The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.
  • Encoded pointers in Tron and Aptos transactions directed infected devices to the same BSC transaction, with Tron serving as the first route and Aptos as a fallback, Chainalysis reported.

Details worth keeping

State-linked hackers accounted for roughly two-thirds of new activity each quarter as the number of times attackers stored malware instructions or infrastructure information on public blockchains rose 420% over the past 12 months, according to a Chainalysis report.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app