Threat actors are increasingly using blockchain dead drops—public-chain transactions and smart contracts that store payload locations, command-and-control (C2) settings, or infrastructure pointers—to make malware operations harder to disrupt. Chainalysis reported that state-linked operators accounted for about two-thirds of newly observed activity per quarter by Q2 2026. The technique does not inherently improve malware capabilities, but lets operators retain C2 coordination after defenders remove domains, hosting, or code repositories.
Reported campaigns include DPRK-linked UNC5342, which used a redundant TRON, Aptos, and Binance Smart Chain relay during fraudulent cryptocurrency-developer job interviews designed to steal credentials; suspected Iranian Ministry of Intelligence-linked operators embedding C2 data in Bitcoin transactions; and Russian-language criminal sellers offering Polygon-based dead-drop infrastructure as malware-as-a-service. EtherHiding has also been associated with web-based malware delivery such as ClearFake and ClickFix activity. Defenders should add endpoint and blockchain telemetry, particularly outbound JSON-RPC requests to public blockchain nodes, rather than indiscriminately blocking all blockchain traffic.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
DPRK-linked UNC5342 began using public-blockchain smart contracts to deliver malware to cryptocurrency developers targeted through fraudulent recruiter and job-interview lures.
Suspected Iranian Ministry of Intelligence-linked operators began embedding encoded C2 routing data in Bitcoin transactions, including small payments sent to an address historically associated with Satoshi Nakamoto.
The Smargaft DDoS botnet used smart-contract-based command-and-control infrastructure hosted on Binance Smart Chain.
After Cloudflare disrupted servers used to deliver its infostealing malware, ClearFake operators adopted EtherHiding on Binance Smart Chain.
Glupteba operators stored malicious information in Bitcoin OP_RETURN fields as part of blockchain-based infrastructure use.
Cybercriminals encoded command-and-control IP addresses for banking malware in Bitcoin transaction amounts denominated in Satoshis.
A Necurs botnet variant used Namecoin to store command-and-control domain information, representing the earliest cited blockchain dead-drop example.
Russian-language cybercriminal operators used Polygon smart contracts as command-and-control dead-drop resolvers in a reported malware-as-a-service operation with an operator panel and subscription model.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcechainalysis.com
Open sourcecertego.net
Open sourcermceoin.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.