Blockchain Dead Drops Surge 420% in Year Amid State-Sponsored Cyber Attacks

Blockchain dead drops—where malicious code instructions and attack infrastructure addresses are hidden on public blockchains—have surged by 420% over the past year. State-backed hackers are leveraging blockchain’s immutability to host command-and-control (C2) infrastructure for malware, according to Chainalysis’ report released on July 17.
Chainalysis explains that dead drops involve storing malicious payloads, C2 settings, and infrastructure pointers within public blockchain transactions or smart contracts for later retrieval by malware. State-linked groups account for nearly half of these activities. The key advantage lies in persistence: unlike centralized servers, which can be taken down via domain seizures or hosting blocks, blockchain-recorded data is harder to remove.
Attackers update transaction addresses on the chain to change C2 server locations, allowing infected devices to fetch new instructions without re-infection. Chainalysis previously reported a 440% increase in such activity within less than a year, with this report detailing North Korea-linked UNC5342 and Iran-associated tactics.
UNC5342 used Tron (TRX) and APTOS (APT) as relay paths to direct devices to malicious instructions stored on Binance Smart Chain (BSC). Transactions on both chains contained encoded pointers leading to the same BSC transaction, with malware first checking Tron before switching to APTOS if needed. Once a path reaches BSC, encrypted C2 server addresses and settings are retrieved.
Iran-linked attackers encoded C2 routing information within Bitcoin (BTC) transactions’ OP_RETURN fields. Controlled wallets sent small amounts to historically significant Bitcoin addresses linked to Satoshi Nakamoto, embedding malicious data in transaction details. Chainalysis noted this was based on analysis of malware types, decoding methods, timing, and C2 infrastructure—not direct government involvement.
Russian-speaking cybercrime groups were found using Polygon (POL) smart contracts as C2 storage, with one operator reportedly renting out malicious code services via multiple stored contracts. Post the rise of high-performance open-source AI models, blockchain entries for malicious data have risen from an average of 2.06 to 11.1 per day, though Chainalysis does not attribute this solely to specific AI tools.
Chainalysis warns that blocking blockchain traffic alone is ineffective; instead, analyzing transaction histories, operational wallets, and contract updates is necessary to trace attack infrastructure and actors.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 최근 1년 새 420% 늘어난 블록체인 데드드롭…국가 연계 해커 확산