FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026
$BTCBitcoin ETFs Hold 6.29% of Supply, Targeting 10% by Mid-2029Sep 30, 2026
FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026
$BTCBitcoin ETFs Hold 6.29% of Supply, Targeting 10% by Mid-2029Sep 30, 2026

State hackers drive 420% onchain malware surge, Chainalysis finds

A 420% surge in onchain malware activity, per Chainalysis, ties to state-linked hacking groups that have moved public blockchain networks into their operational infrastructure. North Korea-linked hackers maintained malware systems on Tron…

By Kwame Asante·Sep 17, 2026·1 min read·crypto

Key takeaways

  • Chainalysis found a 420% surge in onchain malware activity tied to state-linked hacking groups using public blockchain networks as operational infrastructure.
  • North Korea-linked hackers maintained malware infrastructure across three chains: Tron, Aptos, and BNB Chain.
  • Suspected Iran-linked actors embedded operational directions inside Bitcoin transactions rather than hosting separate infrastructure.
  • Chainalysis identified two distinct methodologies: distributed malware hosting across chains versus transaction-level instruction encoding.
  • The North Korea-linked campaign spread malware infrastructure across three distinct chains, while the Iran-linked activity worked at the Bitcoin transaction level.

A 420% surge in onchain malware activity, per Chainalysis, ties to state-linked hacking groups that have moved public blockchain networks into their operational infrastructure. North Korea-linked hackers maintained malware systems on Tron, Aptos, and BNB Chain. Suspected Iran-linked actors embedded directions inside Bitcoin transactions.

Actor Networks Operation
North Korea-linked Tron, Aptos, BNB Chain Malware infrastructure hosting
Suspected Iran-linked Bitcoin Directions embedded in transactions

The Chainalysis findings separate two methodologies. The North Korea-linked campaign distributed malware infrastructure across three distinct chains. The suspected Iran-linked actors worked at the transaction level on Bitcoin, encoding operational instructions into the network itself rather than hosting separate infrastructure on another chain.

Related reading

Share
© 2026 NewsMeter

Frequently asked

How much did onchain malware activity increase according to Chainalysis?

Chainalysis found a 420% surge in onchain malware activity, tied to state-linked hacking groups.

Which blockchains did North Korea-linked hackers use for malware infrastructure?

North Korea-linked hackers maintained malware systems on Tron, Aptos, and BNB Chain.

How did the suspected Iran-linked actors operate differently?

They embedded operational instructions directly into Bitcoin transactions, encoding directions into the network itself rather than hosting separate infrastructure on another chain.

What are the two methodologies Chainalysis identified?

One method distributed malware infrastructure across three distinct chains (North Korea-linked), while the other encoded operational instructions at the transaction level on Bitcoin (suspected Iran-linked).