North Korea and Iran now drive most of a 440% surge in malware hidden on public chains, a technique researchers call impossible to take down.
Chainalysis published its blockchain dead-drop research on September 17, and the headline number recorded a 420% increase over twelve months in malware instructions being written to public blockchains.
The malicious writes went from an average of 2.06 a day to 11.1, roughly a 440% jump. Chainalysis links the change to mid-2025, when open-weight Chinese AI models began appearing without restrictions on generating malicious code. But Eric Jardine, who leads the firm’s cybercrime research, has been careful about what that actually means. He told Bloomberg that blockchains aren't infecting anyone by themselves. The initial compromise still comes through something like a malicious download or a supply-chain attack. The blockchain is just where the malware goes to find out where it should phone home.
And that's what makes the setup so difficult to shut down. Take the North Korean case. UNC5342 hides encoded pointers inside TRON and Aptos transactions, both of which ultimately point to the same BSC transaction. The malware checks TRON first and falls back to Aptos if needed. The BSC transaction contains the encrypted command-and-control addresses in its input data. If the operator wants to change the infrastructure, they can simply broadcast another transaction. Infected machines pick up the new information themselves.
Stopping that attack isn't as simple as taking down one server. You'd have to disrupt the communication path across all three chains. Threat researcher blackorbird also documented the payloads moving through the setup, including JADESNOW and INVISIBLEFERRET, which were distributed through the “Contagious Interview” fake-recruiter campaign.
The Iranian variant caused more damage. Instead of making obvious moves, the wallets sent tiny payments to a well-known Bitcoin address historically associated with Satoshi Nakamoto. The payment itself is basically worthless. The real payload is the encoded data tucked inside the transaction. And because that reference address has nothing to do with the attackers, there's almost no obvious trail leading back to them.
But here's the part that seems to have slipped under the radar , the malware insurgence now more of a service than a technique.
Russian-speaking operators are running resolver contracts on Polygon and renting them out through subscription-style setups, complete with an operator panel and affiliates using the contracts downstream. One deployer wallet has been linked to fraudulent stablecoin impersonation schemes, clipboard hijacking campaigns and more than 50 nearly identical BSC resolvers.
Some newer groups are taking the idea a step further and skipping transactions altogether. Instead, they hide the C2 address inside the bytes of a keyless “phantom” wallet, then send zero-value transactions to it.
That makes the obvious defensive approach pretty useless. You can't simply block Ethereum traffic without also cutting off legitimate infrastructure such as Cloudflare, Infura and Alchemy. And if an attacker wants to, they can just run their own node anyway. Chainalysis' recommendation is to watch what happens at the network level instead, particularly outbound JSON-RPC calls.
The Attack technique already has its own entry in the MITRE ATT&CK framework T1102.002.