// TOM'S HARDWARE US — HARDWARE & GADGET
Blockchain-assisted cyberattacks surge fivefold, driven by Iranian and North Korean state actors, Russia-linked groups
Blockchain dead drops technique stores malicious payloads on blockchains
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Blockchain-assisted cyberattacks have risen more than fivefold since last year, driven largely by North Korean and Iranian nation-state actors and Russian-speaking criminal groups, according to a report by blockchain data and intelligence platform Chainalysis. Rather than storing malicious payloads on servers that are susceptible to disruption, the attackers store them on public, censorship-immune blockchains. The technique, named Blockchain Dead Drops (BDD), stores payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand.
What makes BDD particularly dangerous is that it gives cyberattack campaigns unprecedented durability. Because blockchain data is public, immutable, and replicated worldwide, takedowns become immensely difficult. Threat actors can use this resilient infrastructure for command and control without worrying about losing the layer to domain seizures, repository removals, hosting takedowns, and additional disruptions.
The report notes that the widespread availability of Chinese open-source AI tools has significantly lowered the technical barrier to entry for cybercrime. Meaning that less-experienced attackers can now launch complex cyberattacks, which is linked to a reported 440% rise in BDD attacks.
While blockchain dead drops vary across cyberattack campaigns, attackers typically store either malware payloads or dynamic command-and-control (C2) configuration pointers on the blockchain itself. In C2 setups, the on-chain data does not carry out the attack. Instead, it holds configuration information, such as domains, IP addresses, or other pointers, that direct compromised devices to the attacker’s current infrastructure. Malware on the victim's machine retrieves and decodes this data, which then connects to the real C2 server off-chain, where subsequent commands and malicious activity take place.
In payload-delivery setups, attackers store malicious code or encrypted payload components on-chain for victim machines to retrieve and execute locally. In both cases, once the malware has what it needs, the operation moves off-chain, where the attacker executes the actual compromise, which, depending on the campaign, can mean infostealers targeting crypto wallets and credentials, or remote access trojans that give attackers persistent control over systems.
Chainalysis identified several techniques threat actors use to hide malware on-chain, primarily using transaction-based storage and contract-based storage. In transaction-based storage, attackers publish C2 configurations, payload references, or infrastructure pointers inside blockchain transactions for malware to retrieve later, embedding the data in fields such as memos or calldata. This can occur on a single chain or spread across several blockchains.
On the other hand, contract-based storage uses smart contracts as resilient storage for the same kinds of data, with the contract's state holding the current C2 pointer. This is the model behind EtherHiding, where malware queries the contract for up-to-date information, while the attackers' visible on-chain activity is typically limited to deploying and periodically updating the contract.
Beyond these two approaches, threat actors continue to develop new, less detectable ways to hide malicious data on-chain. One such technique involves “phantom wallets”, blockchain addresses that have no corresponding private key. Instead of placing their C2 server's IP address in a transaction or smart contract, attackers encode it directly into the bytes of the wallet address itself, then send zero-value transactions to that address. Malware on the victim's machine is programmed to decode the IP address from the phantom wallet and connect to the attacker's C2 server.