# Chainalysis reports 420% surge in onchain malware linked to state hackers

> Source: <https://cryptobriefing.com/chainalysis-onchain-malware-state-hackers-surge/>
> Published: 2026-09-17 12:10:03+00:00

Photo: Julio Lopez / Pexels

# Chainalysis reports 420% surge in onchain malware linked to state hackers

North Korean and Iranian cyber groups are now using public blockchains like Tron, Aptos, and BNB Chain as infrastructure for malware operations, according to new findings from the blockchain analytics firm.

State-sponsored hackers aren’t just stealing crypto anymore. They’re building their attack infrastructure directly on top of it.

Chainalysis’s 2026 Crypto Crime Report reveals that North Korea-linked threat actors have begun using public blockchains to host malware payloads and command-and-control instructions. Separately, suspected Iran-linked actors have been embedding operational commands directly into [Bitcoin](https://cryptobriefing.com/markets/bitcoin/) transactions, using the network’s immutability as a feature rather than a bug.

## The numbers behind the threat

North Korean cyber groups stole approximately $2 billion in digital assets over 2025, a 51% increase compared to the prior year. The single largest contributor was the $1.5 billion Bybit exploit. Cumulative theft attributed to North Korea, as tracked by Chainalysis, now exceeds $6.75 billion.

Total illicit cryptocurrency flows reached at least $154 billion in 2025, a 162% year-over-year increase. Sanctioned entities received at least $104 billion in on-chain transactions, up 694% from the previous year. Stablecoins dominated that illicit volume, with Russia’s A7A5 token alone processing over $93 billion.

## Blockchains as malware infrastructure

North Korea-linked groups have been deploying malware payloads and instructions on public blockchains including Tron, [Aptos](https://cryptobriefing.com/markets/aptos/), and [BNB](https://cryptobriefing.com/markets/binancecoin/) Chain. Data stored on a blockchain is immutable and censorship-resistant by design. Once malware instructions are embedded in a transaction, no single entity can take them down. There’s no server to seize, no domain to revoke.

### The news moving money, markets, and the world—before your day starts.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

Iran-linked actors embedded operational directions within Bitcoin transactions themselves. Because Bitcoin’s ledger is permanent and publicly accessible, these embedded commands can be read by malware agents anywhere in the world without raising suspicion from network monitors looking for traditional communication patterns.

## Stablecoins at the center

With stablecoins dominating illicit cryptocurrency volumes in 2025, the findings arrive at a particularly inconvenient moment for the industry. US lawmakers are actively working on stablecoin legislation, with multiple bills advancing through Congress. [Tether](https://cryptobriefing.com/markets/tether/) has previously frozen wallets associated with sanctioned entities, but the scale of flows documented in the report suggests that reactive measures aren’t keeping pace with the problem.

## What this means for the industry

For exchanges and digital asset platforms, compliance teams will need to screen not just for sanctioned addresses but for transactions that might contain embedded malware instructions. The Bybit exploit alone, at $1.5 billion, demonstrated that even major exchanges remain vulnerable to sophisticated state-backed attacks.

North Korean crypto theft increased 51% year-over-year. Sanctioned entity flows surged 694%. Total illicit volumes rose 162%.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
