Key Highlights
- Chainalysis identified more than 15 campaigns and threat-actor clusters using blockchain dead drops.
- Malicious on-chain writes increased from 2.06 to 11.1 per day, a 440% rise in less than a year.
- North Korea- and Iran-linked operators are among the groups using blockchains as part of malware infrastructure.
Public blockchains are increasingly being used as part of malware infrastructure, with attackers storing command-and-control data and infrastructure information in transactions and smart contracts.
According to a Chainalysis report published September 17, the firm identified more than 15 campaigns and threat-actor clusters using what it calls blockchain dead drops (BDDs).
The technique allows malware on compromised devices to retrieve information from public blockchains rather than relying entirely on conventional servers. Chainalysis said malicious blockchain writes increased from an average of 2.06 per day to 11.1 per day, a 440% increase in less than a year.
The firm said state-linked groups, including operators associated with North Korea and Iran, now account for much of the new activity.
How blockchain dead drops work
A blockchain dead drop is a location on a public blockchain where attackers store malware payloads, command-and-control configurations, or pointers to infrastructure.
The information can be embedded in transactions or smart contracts. Malware on an infected device retrieves and decodes the data before connecting to the attacker’s off-chain infrastructure.
The approach does not necessarily replace conventional command-and-control systems. Instead, blockchain data can provide a durable layer for delivering updated infrastructure information even when domains, servers, or repositories used by attackers are disrupted.
Chainalysis said the main advantage is campaign durability rather than greater destructive capability.
“The danger of blockchain dead drops is not greater destructive power. The danger is greater campaign durability.”
Activity rises alongside AI coding tools
Chainalysis linked the increase in BDD activity to the emergence of powerful open-source AI coding models during 2025.
The firm said developing blockchain-based command-and-control infrastructure historically required substantial cybersecurity and blockchain expertise. The availability of open-weight AI models capable of generating code may have lowered some of those technical barriers.
The timing coincides with the increase in malicious blockchain writes from 2.06 to 11.1 per day.
Chainalysis did not establish that AI caused the increase. Instead, it identified the emergence of these models and the subsequent growth in BDD activity as a notable correlation.
State-linked groups drive new activity
The composition of BDD activity has changed over time.
Cybercriminal groups accounted for almost all identified activity through early 2024, according to Chainalysis. State-linked groups became more prominent from the middle of that year.
By Q2 2026, state-linked actors accounted for roughly two-thirds of new BDD activity in each quarter and around half of total activity.
Chainalysis identified activity associated with North Korean, Iranian and Russian-language threat actors.
The firm cautioned that attribution varies by campaign. Its assessment of Iranian activity, for example, relies on malware characteristics, decoding methods, operational timing and related infrastructure rather than blockchain activity alone.
North Korean campaign uses three networks
One campaign involves UNC5342, a North Korea-linked group previously associated with attacks targeting cryptocurrency developers through fake job opportunities.
Chainalysis identified a BDD technique using TRON and Aptos to direct infected devices toward information stored on BNB Smart Chain.
The attackers embed encoded pointers in TRON and Aptos transactions. Malware checks one route and can use the other if the first fails, providing redundancy before retrieving encrypted instructions from BNB Smart Chain.
The BNB Smart Chain transaction contains encrypted malware instructions, including C2 addresses and configuration data, and references to additional on-chain stages.
When attackers change their infrastructure, they can publish updated transaction data rather than modifying malware already installed on victims’ devices.
Chainalysis linked the activity to a BNB Smart Chain deployer previously attributed to UNC5342.
Iran-linked operators use Bitcoin transactions
Chainalysis also identified activity it believes is connected to Iranian state operators using Bitcoin transactions to store command-and-control information.
In the campaign, attackers send small Bitcoin payments to a well-known address with historical links to Satoshi Nakamoto. The payments themselves are not the main purpose of the transactions.
Instead, malware searches the transaction data for encoded information that can be decoded to identify the attackers’ current infrastructure.
Chainalysis said the assessment linking the activity to Iran is based on evidence from the malware and broader operation rather than the Bitcoin transactions alone.
The blockchain therefore functions as a publicly accessible lookup point while the actual malware activity continues through off-chain infrastructure.
Russian-language groups use Polygon
Chainalysis also identified Russian-language cybercriminal groups using Polygon smart contracts to store infrastructure information.
In one campaign, a smart contract acts as a resolver containing the current location of attacker-controlled infrastructure. Operators can update the information when domains or servers are disrupted.
The firm observed one operator wallet controlling multiple resolver contracts, a structure it said is consistent with a malware-as-a-service model in which different contracts may serve separate customers or campaigns.
Chainalysis also linked the broader infrastructure to activity involving fraudulent tokens and campaigns targeting cryptocurrency users.
Public chains create a detection challenge
Using public blockchains creates a challenge for defenders because the same networks support legitimate wallets, exchanges, and decentralized applications.
Chainalysis said simply blocking blockchain traffic would be impractical because it could disrupt legitimate wallets, applications and DeFi services while still leaving attackers able to use alternative infrastructure.
At the same time, public blockchain activity creates a record of transactions, contract deployments and updates.
Investigators can examine transaction histories, resolver contracts, wallet relationships, and related activity to identify connections between infrastructure that might otherwise appear unrelated.
Recent crypto campaigns add context
The findings come as state-linked groups continue targeting cryptocurrency users through different methods.
In July 2026, North Korea-linked BlueNoroff used fake Zoom meeting invitations to distribute malware. The campaign reportedly used trusted Telegram contacts and targeted people involved in crypto, including checking whether potential victims held cryptocurrency before attempting to infect their devices.
That campaign relied on social engineering and malware delivery rather than blockchain dead drops, but it illustrates another method used by state-linked actors targeting cryptocurrency participants.
BDDs add another layer to cyber investigations
The Chainalysis findings show that public blockchains can serve a role in malware infrastructure even when the underlying attack does not involve stealing cryptocurrency.
The report identified BDD activity across five major blockchains and more than a dozen malware strains.
For defenders, this adds another consideration when investigating malware campaigns: blockchain transactions and smart contracts may contain infrastructure information that connects otherwise separate parts of an operation.
The growth in malicious on-chain writes suggests that public blockchains are becoming an additional infrastructure layer for some cybercriminal and state-linked campaigns, while their public records give investigators another source of evidence.
Also Read: MarsCat’s MCAT Surges 186% as Trading Activity Jumps
