Blockchain-assisted cyberattacks surge fivefold, driven by Iranian and North Korean state actors, Russia-linked groups

Blockchain-assisted cyberattacks surge fivefold, driven by Iranian and North Korean state actors, Russia-linked groups

State-level actors entered the scene in 2024, when Iranian actors linked to the country's Ministry of Intelligence first embedded C2 data in Bitcoin transactions. By 2025, North Korean actors began using EtherHiding in fake job interview campaigns . Since then, daily malicious blockchain writes have increased from 2.06 to 11.1, a 440% increase that Chainalysis attributes to AI. Before the launch of powerful open-weight Chinese LLMs — which can be uncensored through a process known as abliteration — building effective BDDs required substantial cybersecurity and crypto experience. Now, far less experienced threat actors can deploy BDDs easily.

Tracking BDD activity across five major blockchains and over a dozen named malware strains, Chainalysis reports that by Q2 2026, “state-actor-linked groups were responsible for roughly two-thirds of new BDD activity each quarter, and half of total BDD activity,” despite only just entering the scene in mid-2024. The campaigns are being perpetrated by Iranian, North Korean, and Russian-speaking operators.

A seemingly obvious fix, blocking blockchain traffic, is out of the question. For example, cutting off Ethereum access would mean blocking every public RPC endpoint that providers such as Cloudflare and Alchemy run. This would also impact legitimate wallets and DeFi services. Even then, the attackers could just go back to running their own nodes off-chain. Similarly, restricting what can be written to a public blockchain at the protocol level is impractical, as the fundamental changes this would require would likely cause more harm than the malware.

This leaves detection, identifying the attackers, and disrupting the off-chain parts of the operation as the only viable options. In this case, the same blockchain properties that make BDD attractive to attackers work against them. Every time an operator rotates infrastructure by publishing a new transaction or updating a contract, the change is permanently recorded and timestamped on a public ledger. By tracing operator wallets, resolver contracts, funding sources, and update histories, investigators can link seemingly unrelated campaigns back to the same actors.

For organizations, one practical early-warning signal is outbound JSON-RPC traffic to public blockchain endpoints, particularly from machines with no legitimate reason to query a blockchain. A workstation or build server reading data from a smart contract should probably sound some warning bells. The technique also maps to an existing MITRE ATT&CK entry, T1102.001 (Web Service: Dead Drop Resolver), giving security teams an established framework for building detections.

In the case of individuals, it's important to note that BDD comes into play only after something malicious is already running on a device. The blockchain tells the malware where to go next, but it doesn't get the malware onto the machine in the first place. North Korea's fake job interview campaigns, for example, still require developers to first download and run malicious code . Therefore, being wary of unsolicited outreach — especially when it involves coding tests that require running unfamiliar repositories — remains the first and most effective line of defense.

Etiido Uko Social Links Navigation News Contributor Etiido Uko is a news contributor for Tom's Hardware covering the latest updates in big tech and the PC industry. He is a mechanical engineer and senior technical writer with over nine years of experience in documentation and reporting. He is deeply passionate about all things engineering and technology, and is an expert in gadgets, manufacturing, robotics, automotive, and aerospace.

Key considerations

  • Investor positioning can change fast
  • Volatility remains possible near catalysts
  • Macro rates and liquidity can dominate flows

Reference reading

More on this site

Informational only. No financial advice. Do your own research.

Leave a Comment