Current outcome
Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity; the newly attributed North Korea-linked UNC5342 group uses Tron, Aptos, and BNB Smart Chain as redundant routes, while Iran-linked actors embed command-and-control routing data in Bitcoin transactions, including those sent to a Satoshi Nakamoto-associated address.
Progress timeline
4 material updates- #01
State hackers drive 420% surge in onchain malware, Chainalysis finds
Chainalysis reports a 420% annual increase in onchain malware activity, with North Korea- and Iran-linked hackers using Tron, Aptos, and BNB Chain transactions to host and route malware infrastructure.
Source evidence: Cointelegraph
- #02
North Korea drives onchain malware surge, CoinEx shuts: Asia Express
Chainalysis attributed previously unattributed activity to North Korea-linked group UNC5342 and said state-linked hackers account for roughly two-thirds of new onchain malware activity.
State after update: Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity, including the newly attributed North Korea-linked UNC5342 group operating across Tron, Aptos and BNB Smart Chain.
Source evidence: Cointelegraph
- #03
Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers
Chainalysis reports blockchain-based malware command-and-control activity surged 440%, with North Korea and Iran-linked hackers accounting for roughly two-thirds of newly observed blockchain dead-drop activity as AI lowers the technical barrier.
Source evidence: CryptoSlate
- #04
Chainalysis: Blockchain Dead Drop Attacks Surge 420% as State Hackers Expand
Chainalysis report added that suspected Iran-linked actors embed command-and-control routing data inside Bitcoin transactions sent to a Satoshi Nakamoto-associated address, and that malicious blockchain writes rose from 2.06 to 11.1 per day (a 440% increase) after the emergence of high-capacity open-weight Chinese AI models.
State after update: Chainalysis reports a 420% year-over-year surge in onchain malware, with North Korea- and Iran-linked hackers responsible for roughly two-thirds of new activity; the newly attributed North Korea-linked UNC5342 group uses Tron, Aptos, and BNB Smart Chain as redundant routes, while Iran-linked actors embed command-and-control routing data in Bitcoin transactions, including those sent to a Satoshi Nakamoto-associated address.
Source evidence: The Defiant