Blockchain Dead Drops Surge 440% as Nation-State Actors Rise

Blockchain-based 'dead drop' activities, where malicious code commands and attack server addresses are hidden on the public ledger, have surged by 440% within less than a year. The combination of blockchain's permanence and AI tools has made traditional domain-blocking approaches insufficient for stopping attacks. Chainalysis reported that daily average malicious command records rose from 2.06 to 11.1 before high-performance open-source AI models emerged, though it cautioned against attributing the increase solely to a specific AI model.
Blockchain dead drops record command-and-control (C2) addresses or next-stage malware locations within transaction data or smart contracts. Infected devices query the public ledger for updated server addresses, allowing attackers to replace off-chain infrastructure via new transactions. While blockchain doesn't automatically execute malicious code, it extends attack campaign lifespans by functioning as a persistent address book.
Attackers have shifted from cybercrime groups to nation-state-linked actors, with Chainalysis noting that two-thirds of observed dead drop activities since Q2 2026 are linked to state-backed operations, accounting for nearly half of all tracked campaigns. Initial attacks were primarily by criminal groups, but state-linked activity became prominent after mid-2024.
North Korea-linked UNC5342 used fake job recruitment targeting crypto developers to deliver malware via smart contracts. Google Threat Intelligence detailed how JADESNOW loader retrieved C2 information from blockchain and downloaded INVISIBLEFERRET backdoor. Separate methods involved TRX (Tron) and APT (Aptos) transactions pointing to encrypted commands stored on BNB Smart Chain, with malware first checking Tron before switching to Aptos if needed.
Iran-linked campaigns inserted C2 routing info into Bitcoin (BTC) transactions sent to addresses historically linked to Satoshi Nakamoto, though these addresses were merely used as reference points. Russian-speaking criminal groups utilized Polygon (POL) smart contracts as command verifiers and offered malware-as-a-service models, enabling attackers without infrastructure to leverage blockchain-based C2.
Defenders must move beyond blocking malicious domains to monitoring wallet activity, smart contract calls, fund movements, update histories, and suspicious JSON-RPC requests. The key is analyzing cross-chain transactions, contract interactions, RPC requests, and wallet flows rather than examining chain-specific data separately.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 블록체인 악성 명령 기록 440% 증가…국가 연계 조직 부상