XIYU.NEWS EVENTS

State hackers drive 420% surge in onchain malware, Chainalysis finds

DevelopingCryptoSecurity incidentFirst tracked 2026-09-17Last changed 2026-09-18

Current outcome

Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity; the newly attributed North Korea-linked UNC5342 group uses Tron, Aptos, and BNB Smart Chain as redundant routes, while Iran-linked actors embed command-and-control routing data in Bitcoin transactions, including those sent to a Satoshi Nakamoto-associated address.

Progress timeline

4 material updates
  1. #01
    Initial2026-09-17 12:00 · publication time

    State hackers drive 420% surge in onchain malware, Chainalysis finds

    Chainalysis reports a 420% annual increase in onchain malware activity, with North Korea- and Iran-linked hackers using Tron, Aptos, and BNB Chain transactions to host and route malware infrastructure.

    Source evidence: Cointelegraph

  2. #02
    Escalation2026-09-17 23:49 · publication time

    North Korea drives onchain malware surge, CoinEx shuts: Asia Express

    Chainalysis attributed previously unattributed activity to North Korea-linked group UNC5342 and said state-linked hackers account for roughly two-thirds of new onchain malware activity.

    State after update: Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity, including the newly attributed North Korea-linked UNC5342 group operating across Tron, Aptos and BNB Smart Chain.

    Source evidence: Cointelegraph

  3. #03
    Confirmation2026-09-18 10:50 · publication time

    Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers

    Chainalysis reports blockchain-based malware command-and-control activity surged 440%, with North Korea and Iran-linked hackers accounting for roughly two-thirds of newly observed blockchain dead-drop activity as AI lowers the technical barrier.

    Source evidence: CryptoSlate

  4. #04
    Escalation2026-09-18 16:59 · publication time

    Chainalysis: Blockchain Dead Drop Attacks Surge 420% as State Hackers Expand

    Chainalysis report added that suspected Iran-linked actors embed command-and-control routing data inside Bitcoin transactions sent to a Satoshi Nakamoto-associated address, and that malicious blockchain writes rose from 2.06 to 11.1 per day (a 440% increase) after the emergence of high-capacity open-weight Chinese AI models.

    State after update: Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity; the newly attributed North Korea-linked UNC5342 group uses Tron, Aptos, and BNB Smart Chain as redundant routes, while Iran-linked actors embed command-and-control routing data in Bitcoin transactions, including those sent to a Satoshi Nakamoto-associated address.

    Source evidence: The Defiant

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.