DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks
2026-09-17 • Chainalysis •
https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops
UNC5342 used public blockchains to deliver credential-stealing malware to cryptocurrency developers targeted through fraudulent job interviews. Chainalysis linked the DPRK operation to a redundant relay in which TRON and Aptos transactions direct infected systems to encrypted instructions stored on BSC, allowing devices to recover updated C2 infrastructure automatically. The technique is designed to survive conventional hosting takedowns and supports remote access, data exfiltration, and cryptocurrency theft. Chainalysis connected the activity to a BSC deployer previously attributed to UNC5342 by Google Threat Intelligence Group.