KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

North Korea-Iran Hacking Group Expands Use of 'Blockchain Dead Drops' for Cyber Attacks

Published September 19, 2026 3:24 AM · 1 views $TRX $APTOS $BNB
North Korea-Iran Hacking Group Expands Use of 'Blockchain Dead Drops' for Cyber Attacks

Blockchain data analytics firm Chainalysis reported on April 18 that the use of "blockchain dead drops" (BDD) for cyber attacks is spreading, with state-linked hacking groups from North Korea and Iran leading the trend. BDD involves attackers recording malicious code or attack instructions on public blockchains, which infected devices then access to continue attacks. Since public blockchains are difficult for any single entity to alter or delete, this method allows attacks to persist even when traditional command-and-control servers are blocked.

Chainalysis noted that the North Korean-linked hacking group UNC5342, tracked by Google Threat Intelligence Group (GTIG) since February 2025, has used BDD. The group lured cryptocurrency developers seeking jobs with fake interview offers to download malware. Infected devices check blockchain records for commands and connect to servers operated by attackers to receive further instructions. Chainalysis linked previously unattributed BDD activity to UNC5342 through on-chain analysis.

The group has distributed attack paths across multiple blockchains including Tron, APTOS, and BNB Smart Chain (BSC). Infected devices first check Tron for information; if that path fails, they switch to APTOS. Both routes connect to encrypted malicious command instructions recorded on BSC. By Q2 2026, state-linked hacking groups accounted for about two-thirds of newly identified BDD activity, with North Korea and Iran-linked organizations both confirmed as using the method. In Russian-language cybercrime markets, services offering Blockchain Dead Drop tools via Malware-as-a-Service (MaaS) have emerged.

Chainalysis analysts also noted that AI adoption has lowered technical barriers for BDD use. After a Chinese high-performance open-weight large language model (LLM) without restrictions on malicious code generation appeared in mid-2025, the average daily number of recorded malicious blockchain entries rose from 2.06 to 11.1.

Jeon Jun-hyuk, managing director of Chainalysis Korea, said: "While state-linked groups are increasingly sophisticated in abusing blockchain technology, the on-chain records they leave behind provide crucial clues for tracking them." He added that using blockchain intelligence to trace these traces and identify attackers and related infrastructure will become increasingly important in responding to new cyber threats.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: “북한·이란 연계 해킹조직, ‘블록체인 데드 드롭’ 활용 확산”