Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Chainalysis Reports Malware Operators Using Blockchains as Command-and-Control Infrastructure

Cybercriminals are increasingly storing malware instructions directly on public blockchains, exploiting their permanent and decentralized nature as a resilient alternative to traditional servers.
1 hour ago 9 views
Chainalysis Reports Malware Operators Using Blockchains as Command-and-Control Infrastructure

Cybercriminals have discovered a new use for public blockchains that extends beyond financial transactions. According to Chainalysis, a growing number of threat actors are storing command-and-control information for malware directly on-chain in what the analytics firm calls Blockchain Dead Drops, or BDDs.

Rather than relying on conventional servers or domains to instruct infected machines, attackers are placing configuration data, addresses, or pointers inside transactions or smart contract state. Malware can then read this information directly from the blockchain, circumventing traditional network defense measures that might shut down a server or seize a domain.

Why Blockchains Attract Malware Operators

Chainalysis describes the broader technique as EtherHiding. Public blockchains present a significant advantage for attackers: once information is written on-chain, it cannot be deleted. This immutability makes blockchains considerably harder to take offline compared to centralized infrastructure.

Attackers can modify the data their malware reads without relying on a conventional web server that could be seized by authorities. The blockchain effectively becomes a resilient public bulletin board that defenders cannot easily dismantle.

Scale of the Activity

According to Chainalysis research, malicious on-chain writes have risen approximately 440% since mid-2025. The research links different forms of the technique to actors associated with North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.

Not a Blockchain Protocol Weakness

Importantly, this technique does not indicate that Bitcoin, Ethereum, BNB Chain, Tron, or other networks have had their underlying cryptography compromised. Attackers are exploiting a feature that blockchains are deliberately designed to provide: public, persistent data storage. This same property allows anyone to verify transactions years after they occur.

The security challenge emerges when malware treats the blockchain's permanent data layer as infrastructure. While malicious software can still be detected and removed from infected devices, the data it relies on may remain publicly accessible indefinitely, creating a persistent problem for defenders and security teams monitoring blockchain activity.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $81,695.90+1.01% EthereumETH $2,645.87+1.99% Tether USDUSDT $0.9993-0.05% BNBBNB $767.07+0.91% XRPXRP $1.43+3.67% USDCUSDC $1.00-0.02% SolanaSOL $111.65+0.18% TRONTRX $0.3383-0.48% HyperliquidHYPE $93.12+1.67% ZcashZEC $1,515.36+2.62%
Prices by Coinranking. Informational only.