Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%
Hackers are using blockchains to keep malware instructions available after servers disappear AI is making blockchain-based malware infrastructure easier for less experienced hackers Blockchain traffic is difficult to block without disrupting legitimate cryptocurrency services worldwide Hackers are i
<![CDATA[ <article> <ul><li><strong>Hackers are using blockchains to keep malware instructions available after servers disappear</strong></li><li><strong>AI is making blockchain-based malware infrastructure easier for less experienced hackers</strong></li><li><strong>Blockchain traffic is difficult to block without disrupting legitimate cryptocurrency services worldwide</strong></li></ul><p>Hackers are increasingly hiding malware instructions inside public blockchains, creating communication channels that can survive the removal of conventional infrastructure.</p><p>New figures from <a href="https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/" target="_blank" rel="nofollow">Chainalysis</a> claim malicious blockchain activity increased 440%, with daily entries rising from 2.06 to 11.1 after newer AI systems emerged.</p><p>The technique gives attackers another way to maintain communication with compromised computers without relying entirely on conventional servers controlled by hosting providers.</p><h2 id="blockchain-networks-become-malware-dead-drops">Blockchain networks become malware dead drops</h2><p>Blockchain dead drops use transaction data or smart contracts as lookup points, allowing infected computers to retrieve commands, addresses, or configuration information.</p><p>Because blockchain records are distributed across networks, removing a conventional server does not erase information already stored on the ledger.</p><p>A North Korean-linked operation associated with UNC5342 uses TRON and Aptos as alternate routes before retrieving encrypted instructions through the BNB Chain.</p><p>Its malware can check one network, switch to another when necessary, and retrieve updated addresses without receiving another malware package.</p><p>Iranian actors suspected of links to the country's intelligence ministry have embedded encoded routing information inside Bitcoin transactions used for malware retrieval.</p><p>Russian-speaking cybercriminals have also commercialized the technique, using Polygon contracts to provide blockchain-backed infrastructure for malware campaigns operated by different customers.</p><p>One related operator controls more than 50 BNB Chain resolver contracts while also conducting activity involving fraudulent tokens and clipboard-monitoring malware.</p><p>These operations show how blockchain records can function as persistent lookup infrastructure rather than merely serving their conventional financial and transactional purposes.</p><h2 id="ai-lowers-the-technical-barrier">AI lowers the technical barrier</h2><p>Chainalysis said the sharp increase in this malicious activity followed the arrival of high-capacity Chinese open models, which placed fewer restrictions on malware development requests.</p><p>Before those systems appeared, building reliable blockchain-based malware infrastructure required expertise across malicious software, cryptocurrency networks, and distributed communication systems.</p><p><a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> can reduce that knowledge barrier by helping less experienced operators understand unfamiliar technologies and produce components needed for blockchain communication.</p><p>In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity.</p><p>Those groups also represent about half of overall observed activity, indicating that blockchain-based malware infrastructure extends beyond conventional cybercriminal operations.</p><p>Defenders face difficulties because blocking blockchain traffic could also disrupt legitimate wallets, decentralized applications, exchanges, and decentralized finance services used worldwide.</p><p>Attackers can further complicate disruption by operating their own blockchain nodes, reducing dependence on external providers that defenders might otherwise pressure or disable.</p><p>Some operators have hidden server addresses inside wallet identifiers without usable private keys, then used zero-value transfers to trigger malware retrieval.</p><p>Those transactions leave public records that investigators can examine, potentially providing useful clues even when attackers attempt to conceal their infrastructure.</p><p>"While the exploitation of blockchain by state-linked organizations such as North Korea is becoming more sophisticated, on-chain records left by attackers can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea.</p><p>"Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly important in responding to new cyber threats."</p><figure class="van-image-figure inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> </article> ]]>
Read the full article on TechRadar
Read Full Article →