Chainalysis Identifies Malware Operators Using Blockchains for Command-and-Control Data
Chainalysis has revealed that cyber attackers are increasingly leveraging public blockchains to store command-and-control information for malware, a practice the firm refers to as 'Blockchain Dead Drops' (BDD). This innovative yet concerning technique enables attackers to utilize the blockchain's public and persistent data layer without compromising its underlying security.
Traditionally, malware relies on servers or domains to communicate with infected machines. However, blocking these domains or seizing servers can disrupt the attackers' operations. In contrast, public blockchains are significantly more resilient against such interventions. By embedding configuration data and instructions within blockchain transactions or smart contracts, attackers can direct malware to retrieve this information directly from the blockchain.
Chainalysis characterizes this broader technique as 'EtherHiding,' where the blockchain serves as a permanent noticeboard for malicious actors. Once data is inscribed on-chain, it becomes nearly impossible for defenders to erase it, making BDDs an appealing choice for command-and-control infrastructure. The firm noted a staggering 440% increase in malicious on-chain activity since mid-2025, linking these tactics to groups associated with North Korea, Iran, and Russian-language cybercrime.
It's crucial to note that this does not indicate a flaw in blockchain protocols like Bitcoin or Ethereum. Instead, attackers are exploiting the inherent features of blockchains, which are designed for public accessibility and data permanence. While malware can be detected and removed from infected systems, the information it relies on may remain accessible indefinitely, posing a significant challenge for cybersecurity professionals.
For operators within the crypto infrastructure, wallet providers, and security teams, the implications are clear: monitoring blockchain activity must now encompass a broader spectrum of threats, including the potential misuse of information itself.
FAQ
What are 'Blockchain Dead Drops' (BDD)?
Blockchain Dead Drops (BDD) refer to a technique used by cyber attackers to store command-and-control information for malware on public blockchains. This allows them to utilize the blockchain's public and persistent data layer without compromising its security.
How does the use of public blockchains benefit malware operators?
Public blockchains provide a resilient infrastructure for malware operators, as they cannot be easily disrupted by blocking domains or seizing servers. Attackers can embed configuration data and instructions within blockchain transactions or smart contracts, allowing malware to retrieve this information directly from the blockchain.
What is 'EtherHiding'?
EtherHiding is a broader technique characterized by Chainalysis, where the blockchain serves as a permanent noticeboard for malicious actors. It allows attackers to inscribe data on-chain, making it nearly impossible for defenders to erase it.
What has been the trend in malicious on-chain activity since mid-2025?
Since mid-2025, there has been a staggering 440% increase in malicious on-chain activity, with tactics linked to groups associated with North Korea, Iran, and Russian-language cybercrime.
What should cybersecurity professionals do in response to these tactics?
Cybersecurity professionals must expand their monitoring of blockchain activity to encompass a broader spectrum of threats, including the potential misuse of information stored on blockchains, as it poses a significant challenge in combating malware operations.
Comments
Comments are moderated before publish.
No comments yet — be the first.