KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

State-Sponsored Hackers Drive 420% Surge in Blockchain Malware

Published September 19, 2026 5:03 AM · 1 views $TRX $ATOM $BNB
State-Sponsored Hackers Drive 420% Surge in Blockchain Malware

According to Chainalysis, the number of times hackers have stored malicious code commands or infrastructure information on public blockchains increased by 420% over the past 12 months, with state-linked hackers responsible for approximately two-thirds of new quarterly activity. Chainalysis identified North Korea and Iran-linked operators among nations adopting this technique. The analysis firm confirmed that previously unattributed activity across Tron, Cosmos, and BNB Smart Chain (BSC) is linked to a North Korea-affiliated group 'UNC5342' tracked by Google Threat Intelligence.

Pointers encoded in Tron and Cosmos transactions directed infected devices to move to the same BSC transaction, with Tron serving as the primary route and Cosmos as a backup. BSC transactions contained encrypted server addresses and configuration data connecting infected devices to offline infrastructure used for remote control and data theft. Chainalysis noted that using public blockchains allows attackers to maintain access to stored information even if domains, servers, or code repositories are shut down, increasing the persistence of malware campaigns. In 2025, North Korean hackers previously used a similar technique called 'EtherHiding' to embed cryptocurrency theft code within smart contracts.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 북한·이란 등 국가 해커들로 인해 주요 블록체인 악성코드 420% 급증