Skip to content

Build1 publisher2 min readPublished

Chainalysis counts a more than fivefold rise in malware that pulls its instructions from public blockchains

Chainalysis says blockchain-assisted cyberattacks, driven mostly by North Korean and Iranian state actors, have risen more than fivefold since last year. The malware reads server addresses or code from public chains, and no seizure or hosting takedown can delete those records.

The Engineer · Build desk

Illustration accompanying Chainalysis counts a more than fivefold rise in malware that pulls its instructions from public blockchains

What happened

  • In the command-and-control variant, the chain holds only domains or IP addresses; the malware decodes them and connects to an off-chain server where the attack actually runs.
  • In the EtherHiding model the current pointer lives in smart-contract state, and the attacker's visible on-chain activity is mostly deploying the contract and updating it now and then.
  • EtherHiding began in mid-2023 after Cloudflare crackdowns blocked infostealer distribution servers, and the ClearFake crew moved its code into smart contracts on BNB.
  • Chainalysis links the growth to Chinese open-source AI tools that let less-experienced attackers launch complex campaigns.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • cost Seizing an attacker's current server costs them one contract update, after which infected machines pick up the replacement address on their next query.
  • constraint Monitoring a single chain can miss transaction-based drops, because attackers can spread pointer data across several blockchains.
  • precedent The 2023 move onto BNB contracts followed a Cloudflare crackdown, so successful infrastructure takedowns can be expected to push more crews on-chain.

Takedowns still reach the off-chain server at the end of the lookup [6]. Chainalysis argues the lookup layer itself survives domain seizures, repository removals and hosting takedowns, because chain data is public, immutable and replicated worldwide [4].

Payload-delivery campaigns skip the server even for the first stage. The malicious code, or encrypted pieces of it, sits on-chain for the victim machine to fetch and run locally [7]. For that step there is no host to take down [7]. The damage still happens off-chain afterwards, through infostealers aimed at crypto wallets and credentials, or remote access trojans that give the attacker persistent control [8].

Phantom wallets are the neatest piece of engineering in the report. The attacker encodes the C2 server's IP address into the bytes of a wallet address that has no private key, then sends zero-value transactions to it [11]. No memo field or contract holds the data. The address is the data, and the malware is built to decode it [11].

The technique is old. A Necurs botnet variant kept its C2 domain on Namecoin, a Bitcoin fork, in 2013 [12]. In 2019, banking malware carried C2 IP addresses inside Bitcoin transactions, and the Glupteba mining botnet stored data in Bitcoin's OP_RETURN field [13].

Chainalysis puts the rise at more than fivefold since last year and also cites a 440% increase in dead-drop attacks [1][5]. A 440% rise is 5.4 times the earlier level, so the two figures agree [1]. The coverage does not give the underlying attack counts, so the multiple alone does not show how many campaigns are involved.

Every variant shares one step. Code on the victim's machine reads chain data before it contacts anything the attacker could lose [3][6]. In my view that read is where detection belongs. It comes first in each variant the report describes, and it is the one step the attacker cannot move off the chain [6][7]. The public ledger also helps the defender. The attacker gets a replicated config store with an audit log it cannot delete, and so does anyone investigating it. Contract state that hands infected machines their current pointer can be read by anyone with the contract address, though the malware still decodes what it reads [4][10][6].

What to watch

  • Whether phantom-wallet encoding spreads beyond the campaigns Chainalysis has seen, since it leaves no memo or contract data to scan.
  • Whether Chainalysis or others show how attacks were attributed to less-experienced operators using open-source AI tools, which would test the report's causal link.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories