Blockchain-assisted cyberattacks surge fivefold, Chainalysis report finds

North Korean and Iranian state actors among groups using 'blockchain dead drops' to store malware payloads on immutable ledgers

By LineZotpaper
Published
Read Time2 min
Blockchain-assisted cyberattacks have risen more than fivefold since last year, driven largely by North Korean and Iranian nation-state actors and Russian-speaking criminal groups, according to a new report from blockchain intelligence firm Chainalysis.

The report details a technique the researchers call Blockchain Dead Drops (BDD). Instead of storing malicious payloads on servers that can be disrupted, attackers store them on public blockchains, where data is public, immutable and replicated worldwide. Infected devices retrieve the payloads on demand.

This durability is what makes BDD dangerous. Because blockchain data cannot easily be removed, takedowns become immensely difficult. Threat actors can use the infrastructure for command and control without worrying about domain seizures, repository removals, hosting takedowns or other disruptions.

The report identifies two main storage approaches. In transaction-based storage, attackers embed command-and-control configurations, payload references or infrastructure pointers inside blockchain transactions, in fields such as memos or calldata, on a single chain or across several. In contract-based storage, smart contracts hold the data, with the contract's state containing the current C2 pointer. This is the model behind EtherHiding, where malware queries the contract for up-to-date information while the attacker's visible on-chain activity is limited to deploying and periodically updating the contract.

BDD is used in two kinds of setups. In command-and-control configurations, the on-chain data holds configuration information, such as domains or IP addresses, that directs compromised devices to the attacker's current infrastructure off-chain. In payload-delivery setups, malicious code or encrypted payload components are stored on-chain for victim machines to retrieve and execute locally. In both cases, the actual compromise moves off-chain, and can involve infostealers targeting crypto wallets and credentials, or remote access trojans that give attackers persistent control over systems.

Chainalysis also links the rise in attacks to the widespread availability of Chinese open-source AI tools, which the report says have significantly lowered the technical barrier to entry for cybercrime, allowing less experienced attackers to launch complex attacks. The report puts the increase in BDD attacks at 440%.

§

Analysis

Why This Matters

  • Blockchain dead drops make takedowns nearly impossible: campaign infrastructure survives domain seizures, repository removals and hosting disruptions, giving attacks unprecedented durability.
  • Nation-state actors are driving the surge, raising concerns for government networks, critical infrastructure and financial systems that may be the targets of their campaigns.
  • Open-source AI tools are lowering the barrier to entry, potentially widening the pool of groups able to run sophisticated blockchain-assisted attacks.

Background

Blockchains are distributed ledgers designed to be public, immutable and resistant to censorship. Those same properties, intended to protect users from unilateral control, also make the technology attractive to attackers seeking resilient infrastructure. Traditional cybercrime takedowns rely on seizing domains and servers, but on-chain data is replicated across the globe, so there is no single point of failure to remove. The technique adapts the long-established concept of a dead drop, where parties leave data at a prearranged location, to a decentralized network that no single authority controls.

Key Perspectives

Chainalysis and security researchers: BDD represents a meaningful evolution in attack resilience, turning public blockchains into durable command-and-control infrastructure that is difficult to disrupt and can be updated by attackers at will. Defenders and incident responders: Standard disruption playbooks are less effective against on-chain infrastructure; defenders are likely to need new detection methods that monitor blockchain activity for malicious patterns and focus on cutting off the off-chain components of campaigns. Skeptics: The scale of the increase may partly reflect improved detection of a technique that has existed in various forms, and the practical threat depends on whether campaigns can shift the bulk of their operations on-chain without exposing themselves to monitoring.

What to Watch

  • Whether ransomware operations and other financially motivated groups beyond the named state actors begin adopting BDD techniques.
  • Defensive responses, including blockchain monitoring tools and takedown efforts aimed at the off-chain C2 layer that attackers still depend on.
  • Further use of open-source AI tools to automate the deployment of blockchain-assisted attacks, which could accelerate the reported growth.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.