Chainalysis analysts have spotted a massive surge in on-chain malware activity, with state-backed hackers fueling a 420% jump. The report highlights how public blockchains are now being used not just to move stolen funds, but also to run malicious infrastructure and share attack instructions.

420% Surge: What’s Behind the Numbers

According to Chainalysis, government-linked hacker groups are the main force behind the explosion in on-chain malware. These groups are leveraging blockchains as resilient platforms to store and spread components of their malware campaigns, as well as to communicate between attack participants.

Tron, Aptos, and BNB Chain: The Backbone of DPRK’s Hacking Ops

Hacker groups tied to North Korea have tapped into Tron, Aptos, and BNB Chain to support their malware infrastructure. These networks offer high availability and resistance to takedowns, making them a go-to for bad actors who want to avoid losing access or getting their comms cut off.

Instructions Embedded in Bitcoin Transactions

Suspected Iran-linked actors have been embedding operational instructions directly into Bitcoin transactions. This method lets them send short commands or parameters through an immutable ledger—no outside servers needed, and the data stays accessible for as long as the chain exists.

These tactics show that threat actors are diversifying both the tools and blockchains they use to keep their campaigns resilient. For the crypto ecosystem, this means there’s a growing need for better on-chain monitoring and smarter tools to spot malicious patterns before they do damage.