Blockchain Dead Drop Attacks Surge 440% as State Actors Leverage On-Chain Infrastructure

Generated byAinvest Coin BuzzReviewed byThe Newsroom
Thursday, Sep 17, 2026 9:21 pm ET4min read
APT--
BTC--
ETH--
IMX--
T--
Aime RobotAime Summary

- State-sponsored groups from North Korea and Iran dominate blockchain dead drops (BDDs), using public blockchains to host malware C2 infrastructure resistant to takedowns.

- Open-source AI models have lowered technical barriers, enabling 440% growth in malicious on-chain writes since mid-2025 across chains like BSC, TRONTRON--, and BitcoinBTC--.

- Attackers leverage blockchain immutability for campaign longevity, with UNC5342 using multi-chain relays and Iranian actors embedding C2 data in Bitcoin transactions.

- Defenders face challenges as blocking blockchain traffic disrupts legitimate services, requiring blockchain intelligence platforms to track immutable on-chain rotations and adversary patterns.

  • Threat actors, particularly state-sponsored groups from North Korea and Iran, are increasingly using public blockchains to host malware command-and-control instructions, creating persistent infrastructure that resists traditional takedowns.
  • Nation-state operators now represent roughly two-thirds of new Blockchain Dead Drop (BDD) activity, leveraging AI-generated code to automate malicious writes and ensure campaign longevity.
  • The primary driver of this surge is the availability of unrestricted open-source AI models, which have significantly lowered the technical barrier for deploying complex BDDs across multiple chains.
  • This shift from cybercriminals to state actors reflects a strategic move toward long-term campaign durability, prioritizing resilience against infrastructure disruptions over immediate destructive power.

Cyber threat actors are increasingly utilizing public blockchains to hide malware instructions, creating "blockchain dead drops" (BDDs) that make command-and-control (C2) infrastructure nearly impossible to seize or take down. Research by Chainalysis indicates that nation-state operators, specifically those linked to North Korea and Iran, now represent the majority of this activity. BDDs store payloads in on-chain transactions and smart contracts, allowing infected devices to retrieve instructions on demand. This permanence ensures campaign longevity, as blockchains are censorship-resistant and cannot be taken offline like traditional centralized servers.

The adoption of this technique has accelerated dramatically, with malicious blockchain writes increasing by 440% since the launch of high-capacity, open-source Chinese AI models that lack restrictions on generating malicious code. These tools have removed the historical barrier to entry, allowing less-experienced actors to deploy complex BDDs. Nation-state actors are refining techniques introduced by cybercriminals, such as "EtherHiding," which embeds malicious code in smart contracts on EVM-compatible chains like Binance Smart Chain (BSC).

Specific case studies highlight distinct operational methods. North Korean-linked group UNC5342 utilizes a cross-chain relay strategy involving TRON, AptosAPT--, and BSC. Infected devices first query TRON; if that fails, they query Aptos, both directing them to a BSC transaction containing encrypted C2 data. This redundancy makes disruption difficult, as attackers must act across multiple chains simultaneously.

Iranian actors linked to the Ministry of Intelligence have embedded C2 routing data in BitcoinBTC-- transactions, specifically within the OP_RETURN field, using a well-known Satoshi-era address as a permanent lookup point. Meanwhile, Russian-language cybercriminal groups are employing a Malware-as-a-Service model on Polygon, using smart contracts as programmable storage for C2 resolvers managed by a central operator.

Why Are State Actors Dominating On-Chain Malware Infrastructure?

The surge in BDDs, up 440% since mid-2025, is attributed to the launch of high-capacity open-source Chinese AI models that lack restrictions on generating malicious code. Historically, building effective BDDs required substantial cybersecurity expertise, but these tools have democratized access, allowing less-experienced actors to deploy complex C2 infrastructure across multiple chains like Bitcoin, EthereumETH--, TRON, Aptos, and Polygon.

While cybercriminals accounted for nearly all activity through early 2024, state-linked groups produced roughly two-thirds of new activity by Q2 2026. This shift reflects a strategic move toward long-term campaign durability. Defenders face significant challenges as blocking blockchain traffic would disrupt legitimate DeFi and wallet services.

The danger lies in the longevity of these campaigns rather than an increase in destructive capability. By storing data on immutableIMX-- public blockchains, attackers ensure that command-and-control infrastructure remains accessible even if traditional domains, servers, or code repositories are seized or taken offline.

How Are Defenders Adapting To Takedown-Resistant Tactics?

Defenders face challenges as blocking blockchain traffic would disrupt legitimate services. Instead, blockchain intelligence platforms are essential for detecting these immutable, timestamped on-chain rotations, mapping operator wallets, and profiling adversaries to tailor responses. Every on-chain rotation is permanent and timestamped, allowing analysts to map operator wallets and attribute campaigns .

Monitoring outbound JSON-RPC calls to public blockchain endpoints serves as a scalable early-warning signal for organizations with endpoint visibility. Blockchain intelligence offers a path forward by leveraging the immutability of these networks. This approach allows defenders to track the evolution of attack infrastructure and identify patterns in adversary behavior .

The technique has evolved from early Bitcoin forks like Namecoin in 2013 to modern EVM chains, with groups like UNC5342 implementing complex multi-chain relays to evade detection. Chainalysis has identified over 15 campaigns and threat-actor clusters utilizing BDDs, highlighting the scale of this emerging threat vector .

Daily malicious on-chain writes climbed from 2.06 to 11.1 in under a year. Chainalysis describes this technique as "blockchain dead drops" (BDDs), where state-linked operators from North Korea and Iran now generate most of the activity. The firm notes that while the technique dates back to 2013 with the Necurs botnet on Namecoin, it has evolved significantly, reaching Ethereum Virtual Machine chains in 2023 via EtherHiding .

The recent explosion in activity is pinned to mid-2025, when powerful open-weight Chinese models launched without safeguards against writing malicious code. This erased the skill barrier that previously kept dead drops rare. While Chainalysis could not definitively prove AI usage in every instance, they noted a clear temporal association between models and the spike in activity.

North Korea’s UNC5342 group, for instance, runs a three-chain relay using TRON and Aptos to steer infected devices to BNB Smart Chain, rotating infrastructure by publishing new transactions that all infected devices automatically pick up. This method bypasses traditional defenses like domain seizures or hosting takedowns .

Iranian operators have similarly utilized Bitcoin to store encoded command-and-control routing data, often sending small payments to addresses historically tied to Satoshi Nakamoto to mask their activity. This technique ensures that compromised devices can always retrieve updated attack instructions, making disruption significantly more difficult for defenders compared to traditional web2 infrastructure.

Russian-language cybercriminal groups utilize Polygon smart contracts for Malware-as-a-Service (MaaS) operations. These smart contracts act as resilient C2 resolvers, allowing a central operator to manage the distribution of malware instructions to a wide network of compromised devices .

The shift from cybercriminals to state actors reflects a strategic move toward long-term campaign durability. By leveraging the immutability of public blockchains, these groups can maintain operational longevity even after traditional hosting infrastructure is seized or blocked. This trend is expected to continue as AI tools further lower the technical barriers for deploying complex on-chain malware infrastructure .

Defenders must adapt their strategies to account for this new reality. Traditional takedown methods are no longer effective against blockchain-based C2 infrastructure. Instead, organizations must invest in blockchain intelligence and on-chain analytics to detect and mitigate these persistent threats. The rise of state-sponsored blockchain dead drops represents a significant evolution in cyber warfare, with implications for global security and digital asset safety .

The availability of unrestricted open-source AI models has fundamentally changed the landscape of cyber threats. By automating the creation of malicious code, these tools have enabled a wider range of actors to deploy sophisticated attacks. The result is a surge in blockchain-based malware infrastructure that is both more resilient and more difficult to disrupt .

As state actors continue to refine their use of blockchain dead drops, the need for robust defensive measures becomes increasingly critical. The immutability of public blockchains, once seen as a benefit for transparency and security, is now being exploited to hide malicious activity. This paradoxT-- highlights the dual-use nature of blockchain technology and the challenges it poses for cybersecurity .

The trend of using public blockchains for malware infrastructure is likely to persist as long as the technical barriers remain low. The introduction of AI tools has made it easier for threat actors to deploy complex BDDs, and there is no indication that these barriers will rise in the near future. Consequently, defenders must remain vigilant and adaptive in their approach to combating these evolving threats .

Blending traditional trading wisdom with cutting-edge cryptocurrency insights.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet