Based on a Chainalysis study, government-backed hackers drove approximately two-thirds of the fresh activity each quarter as instances of attackers embedding malicious software instructions or system data onto public blockchains surged by 420% over the past year.
Chainalysis pinpointed operators tied to North Korea and Iran among the state actors utilizing this approach. In one of the study’s conclusions, the blockchain analysis firm linked previously unassociated operations spanning BNB Smart Chain (BSC), Aptos, and Tron to UNC5342, a Pyongyang-associated cell tracked by Google Threat Intelligence.
Obfuscated indicators within Tron and Aptos transfers directed infected systems to an identical BSC transaction, with Tron acting as the primary pathway and Aptos functioning as a backup, Chainalysis detailed. The BSC transaction held encrypted server endpoints and setup parameters that linked compromised machines to offchain infrastructure designed for data extraction and remote administration.
Chainalysis stated that leveraging public ledgers enhances the longevity of malware operations because the recorded details stay reachable even after code repositories, servers, or web domains are dismantled. During 2025, North Korean threat actors employed a comparable technique known as EtherHiding to embed crypto-draining code inside smart contracts.

AI tools accelerate malicious writes
The firm additionally documented a 440% growth in harmful blockchain writes starting from July 2025, a timeframe when it noted that high-capacity open-source Chinese artificial intelligence models gained the ability to generate malicious code with minimal safeguards.
Eric Jardine, cybercrime research manager at Chainalysis, informed Cointelegraph that they found a distinct temporal correlation, though they could not definitively prove that the individuals publishing the dangerous transactions and contracts relied on those models to boost their output.
Related: Iran eases currency rules to bypass US sanctions with crypto: Report
Iran-linked actors put malware directions on Bitcoin
Chainalysis also uncovered threat groups it suspects are connected to Iran’s Ministry of Intelligence embedding scrambled command-and-control routing details directly onto the Bitcoin ledger.
The enterprise clarified that its evaluation relied on the malware family, decoding strategy, timing, and server architecture tied to past Iranian campaigns, rather than depending solely on the ledger activity.
Wallets controlled by the hackers transmitted nominal amounts to a prominent Bitcoin address with historical associations to Bitcoin creator Satoshi Nakamoto, according to the findings. Chainalysis noted that the destination had zero connection to the perpetrators and functioned as an enduring public point that compromised systems could check for updated guidance.
The malicious operators could modify their server infrastructure by broadcasting another Bitcoin transaction, following which the infected machines would automatically pull down the fresh details. Once the malware secured those directives, the operation transitioned offchain for tasks that might involve credential theft, remote administration, and the deployment of extra malware.
Magazine: Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it
Originally published at https://cointelegraph.com/news/onchain-malware-writes-surge-420-north-korea-iran-chainalysis?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound.