Recently, it has been found that hacking organizations with national backgrounds such as North Korea.. | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Chainalysis Announces Latest Trends in Cyber Threats
Hacking Organizations Behind Countries such as North Korea and Iran

CHANNELISIS

Recently, it has been found that hacking organizations with national backgrounds such as North Korea and Iran are widely spreading the “Blockchain Dead Drops” method, which exploits public blockchains for cyberattacks.

Even if existing hacking servers or domains are blocked, attacks can be continued for a long time, putting the cybersecurity industry on alert.

On the 18th, blockchain data platform Chainalysis announced the latest cyber threat trends. BDD refers to a method in which an attacker records malicious code or commands and access information necessary for an attack on a public blockchain to persistently hack.

Once the information recorded on the public blockchain is very difficult for a specific subject to delete or stop arbitrarily, so infected devices can check the information on the blockchain at any time and resume hacking attacks.

Cases of actual use of North Korea-linked hacking organizations were also revealed. It has been confirmed that the North Korean-linked organization, which has been closely tracking since February last year by Google Threat Intelligence Group (GTIG), has induced virtual asset developers looking for jobs to download malicious codes under the guise of fake job interviews.

After that, the infected victim’s device will continue to read commands recorded on the blockchain and access the hacker-run server to be further attacked.

Through on-chain analysis, Chainalysis was able to link BDD activities that were previously unclear to these North Korean organizations (UNC5342).

They are characterized by distributing attack routes to a number of blockchains such as TRON, Aptos, and BNB Smart Chain (BSC).

It is designed to connect the infected device to the BSC with a malicious code command encrypted by using Aptos if the infected device checks the information first on the Tron and if the route does not work.

This suggests that even if an attacker changes the server along the way, if only new access information is recorded again on the blockchain, the infected device can check it and continue hacking.

◆ Two-Thirds of New BDD National Organizations…中 Open weight LLM lowers barriers to entry

The use of BDD is rapidly expanding around state-linked organizations. As of the second quarter of 2026, state-linked organizations accounted for about two-thirds of new BDD activities.

The use of Iranian-linked organizations as well as North Korea has been confirmed, and Malware-as-a-Service (MaaS) that sells BDD toolkits or provides them in the form of subscriptions has also appeared in the Russian-speaking cybercrime ecosystem.

The spread of AI was also pointed out as a factor that lowered technical barriers to entry.

In the past, a high level of cybersecurity and blockchain expertise was needed, but with the emergence of a high-performance Chinese open weight large-scale language model (LLM) that does not limit the generation of malicious codes in mid-2025, even inexperienced attackers have become easier to use BDD.

In fact, the number of malicious information records in the blockchain tracked by Chainalysis has more than tripled from an average of 2.06 cases per day before the AI model appeared to 11.1 cases since then.

“Although blockchain abuse by state-linked organizations such as North Korea is becoming more advanced, the on-chain records left by attackers are rather an important clue to track them,” said Kwon Joon-hyuk, head of Chanellis Korea. “Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become more important in responding to new cyber threats.”



Click Here For The Original Source.

——————————————————–

..........

.

.