Home NorthKorea How North Korean and Iranian Hackers Exploit Blockchain: 2026’s Rising Cyber Threats

How North Korean and Iranian Hackers Exploit Blockchain: 2026’s Rising Cyber Threats

0
/ News1
/ News1

State-sponsored hacking groups from countries like North Korea and Iran are increasingly exploiting public blockchains as covert channels for cyber attacks. In the second quarter of this year, roughly two-thirds of newly identified Blockchain Dead Drop (BDD) activities were traced back to these state-affiliated organizations.

On Friday, blockchain analysis platform Chainalysis released its findings on BDD activities.

BDD is a technique where attackers record attack-related information on the blockchain to transmit commands to compromised devices. When hackers upload access details or malware data to the blockchain, infected devices retrieve this information to execute attacks.

Unlike conventional cyber attacks, where blocking the attacker’s command and control (C2) server can halt operations, BDD exploits the blockchain’s immutability. This means attacks can persist even if specific servers are taken down, as the information remains on the blockchain.

Concrete examples of North Korean-linked hacking groups using BDD have been documented. The Google Threat Intel Corporationligence Group (GTIG) has been monitoring an entity codenamed UNC5342 since February last year. This group targeted job-seeking cryptocurrency developers with fake interviews, tricking them into downloading malware. The infected devices then retrieved access information from the blockchain to connect to the attacker’s server.

North Korea isn’t the only nation-state utilizing BDD. Analysis of new BDD activities in Q2 this year revealed that about two-thirds were attributed to state-sponsored groups, with Iranian-linked organizations also detected.

Experts warn that the rise of artificial intelligence (AI) is lowering the barrier to entry for BDD attacks. Chainalysis noted that the emergence of unrestricted, high-performance open-source large language models (LLMs) from China has made it easier for less sophisticated attackers to leverage BDD techniques.

However, the inherent properties of blockchain technology can also aid in tracking these attackers. The immutable nature of blockchain transactions and data records works both ways.

Kwon Jun-hyuk, head of Chainalysis Korea, emphasized that on-chain records left by attackers can provide valuable leads for investigators. He stressed that tracing these digital footprints through blockchain Intel Corporationligence and mapping out attacker-related infrastructure will be crucial in countering evolving cyber threats.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version