A 420% surge in onchain malware activity, per Chainalysis, ties to state-linked hacking groups that have moved public blockchain networks into their operational infrastructure. North Korea-linked hackers maintained malware systems on Tron, Aptos, and BNB Chain. Suspected Iran-linked actors embedded directions inside Bitcoin transactions.
| Actor | Networks | Operation |
|---|---|---|
| North Korea-linked | Tron, Aptos, BNB Chain | Malware infrastructure hosting |
| Suspected Iran-linked | Bitcoin | Directions embedded in transactions |
The Chainalysis findings separate two methodologies. The North Korea-linked campaign distributed malware infrastructure across three distinct chains. The suspected Iran-linked actors worked at the transaction level on Bitcoin, encoding operational instructions into the network itself rather than hosting separate infrastructure on another chain.