State hackers drive 420% surge in onchain malware, Chainalysis finds

North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.
State-linked hackers accounted for roughly two-thirds of new activity each quarter as the number of times attackers stored malware instructions or infrastructure information on public blockchains rose 420% over the past 12 months, according to a Chainalysis report.
Chainalysis identified North Korea and Iran-linked operators among the state actors adopting the technique. In one of the report’s findings, the analytics firm connected previously unattributed activity spanning Tron, Aptos and BNB Smart Chain (BSC) to UNC5342, a North Korea-linked group tracked by Google Threat Intelligence.
Encoded pointers in Tron and Aptos transactions directed infected devices to the same BSC transaction, with Tron serving as the first route and Aptos as a fallback, Chainalysis reported. The BSC transaction contained encrypted server addresses and configuration data that connected compromised devices to offchain infrastructure used for remote access and data theft.
Source: Cointelegraph →Related News
- 1 hour ago
Stablecoin payments firm dtcpay closes $25M round with SBI backing
- 2 hours ago
Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment
- 6 hours ago
Zcash targets November for NU7 mainnet upgrade with 25-second blocks
- 6 hours ago
Cardano’s IOG warns users to avoid YouTube channel amid apparent hijack
- 6 hours ago
Cardano’s IOG warns users to avoid YouTube channel amid giveaway scam
