State-linked cybercriminal groups have driven a dramatic increase in onchain malware activity, with new attacks stored on public blockchains rising by 420% over the past year, according to Chainalysis. The surge reflects a strategic shift by actors—including those tied to North Korea and Iran—as they exploit blockchain’s permanence to persist beyond traditional infrastructure takedowns. In one notable case, Chainalysis traced previously unattributed malware campaigns across Tron, Aptos, and BNB Smart Chain to UNC5342, a North Korea-affiliated group. Infected devices received encoded commands via Tron and Aptos transactions, directing them to a BSC transaction containing encrypted server addresses and configuration data for remote access and data exfiltration. The technique mirrors past tactics like EtherHiding, where North Korean hackers embedded crypto-stealing code in smart contracts in 2025.
State-backed hackers exploit onchain malware surges 420% in 2024
Chainalysis highlights rising use of public blockchain-based malware by North Korea and Iran-linked actors, leveraging AI-assisted techniques to evade takedowns.
MW
Marcus Webb · Crypto Desk · 18 Sept 2026 · 03:48 · 1 min read
This article was produced with AI assistance and edited by a Finance Review Daily journalist.
ADVERTISEMENT

MW
Written by
Marcus Webb
Crypto Desk
Marcus reports on digital assets, from spot ETF flows to protocol-level developments in DeFi. He pays particular attention to how institutional adoption is reshaping crypto market structure.
More from Marcus Webb →










