TheCryptoNews.eu
Security

Chainalysis: Cybercriminals Are Using Public Blockchains to Host Malware Instructions

Chainalysis Warns Malware Operators Are Turning Blockchains Into Needless Drops

Cybercriminals are increasingly using public blockchains to store instructions that malware can retrieve, according to blockchain analytics firm Chainalysis. The company refers to the technique as “Blockchain Needless Drops” (BDDs), a form of infrastructure designed to make malware command-and-control systems harder to disrupt.

Blockchains Used as Persistent Noticeboards

Traditional malware operations often depend on a web domain or centralized server to tell infected devices what to do next. Security teams can target that infrastructure by taking down the domain, seizing the server or blocking access.

Under the approach described by Chainalysis, attackers instead place configuration data, wallet addresses or other instructions inside blockchain transactions or smart contract state. Malware is then programmed to read the information directly from the network. Because blockchains maintain public and continuously available records, the data can remain accessible even if the original attackers lose control of their other infrastructure.

Chainalysis places the broader tactic within what it calls “EtherHiding.” The method does not involve taking over a blockchain or altering its underlying protocol. Rather, criminals are using the network as a resilient public bulletin board whose records cannot simply be deleted by defenders.

Malicious On-Chain Activity Has Increased

According to Chainalysis, malicious blockchain writes associated with these techniques have risen by about 440% since mid-2025. The firm’s analysis connects different examples to threat actors linked to North Korea and Iran, as well as financially motivated Russian-language cybercrime groups.

Those attribution findings reflect Chainalysis’ own research. The company says the growing use of blockchains for malware-related data creates a problem for security teams: removing malware from an infected device may not eliminate the public information that the program relies on.

Not a Cryptographic Attack

The activity does not indicate that Bitcoin, Ethereum, BNB Chain, Tron or other networks have had their cryptography compromised. Instead, attackers are exploiting a normal feature of public blockchains—their transparent and persistent data layer—as part of their command-and-control infrastructure.

For wallet providers, crypto infrastructure operators and cybersecurity teams, Chainalysis’ findings suggest that blockchain monitoring may need to look beyond stolen assets and suspicious transfers. In some cases, the threat may be contained in the data being written to the chain itself.

Leave a Comment

Or Login with

[woo_social_login]

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More