TL;DR
- Chainalysis detected a 420% growth in the use of public blockchains to store malware infrastructure over twelve months.
- Actors linked to North Korea used Tron, Aptos and BNB Chain, while groups tied to Iran embedded instructions in Bitcoin transactions.
- Since July 2025, malicious records on the blockchain have increased 440%, coinciding with the arrival of open source AI models capable of generating harmful code.
The blockchain analytics firm Chainalysis published a report revealing a 420% increase in the number of times attackers stored malware instructions or infrastructure information on public blockchains over the past twelve months. State actors accounted for approximately two thirds of the new activity recorded each quarter.
Among the identified groups are criminals linked to North Korea and Iran. Chainalysis connected previously unattributed activity on Tron, Aptos and BNB Smart Chain to the group UNC5342, tracked by Google Threat Intelligence and associated with Pyongyang.
According to the report, pointers encoded in Tron and Aptos transactions directed infected devices toward a single transaction on BSC, where encrypted server addresses and configuration data were stored, connecting compromised machines to offchain infrastructure used for remote access and data theft.
Blockchains as a Shield for State Malware
The firm explained that the use of public blockchains increases the durability of malware campaigns because the stored information remains accessible even when domains, servers or code repositories are taken down. In 2025, North Korean hackers had already employed a similar technique known as EtherHiding to insert cryptocurrency-stealing code into smart contracts.
Chainalysis also recorded a 440% increase in malicious records on the blockchain since July 2025, a date that coincides with the availability of high-capability open source artificial intelligence models with limited safeguards. Eric Jardine, the company’s cybercrime research director, noted that there is “a clear temporal association,” while clarifying that it is not possible to prove that the responsible actors used those models to scale their output.
Chainalysis: Iran Uses Bitcoin as a Command Vector
Chainalysis also identified actors it believes are linked to the Ministry of Intelligence of Iran writing encoded routing data directly onto the Bitcoin blockchain. The assessment was based on the malware family, the decoding method, the timing of the records and the server infrastructure associated with previously documented Iranian operations.
Wallets controlled by the attackers sent small-value payments to an address with historical ties to Satoshi Nakamoto, used as a permanent public reference point from which infected devices retrieved updated instructions. Once that information was obtained, the operation continued offchain for activities that could include remote access, credential theft and delivery of additional malware.





