← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Blockchain-assisted cyberattacks surge fivefold, driven by state actors and criminal groups

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Blockchain-assisted cyberattacks increased over fivefold.
  • Iranian, North Korean, and Russian groups are primary drivers.
  • BDD stores malicious data on public, immutable blockchains.
  • Open-source AI tools lower entry barrier for cybercrime.
  • Takedowns of BDD infrastructure are difficult due to blockchain properties.

Surge in Blockchain-Assisted Cyberattacks

Blockchain-assisted cyberattacks have seen a more than fivefold increase since last year. This surge is largely attributed to nation-state actors from North Korea and Iran, as well as Russian-speaking criminal organizations. The technique, termed Blockchain Dead Drops (BDD), involves storing malicious payloads or command-and-control data on public, censorship-resistant blockchains.

Enhanced Durability of Cyber Campaigns

The BDD technique provides cyberattack campaigns with increased durability. By leveraging the public, immutable, and globally replicated nature of blockchain data, attackers make their infrastructure highly resistant to disruption. This resilience prevents takedowns through domain seizures, repository removals, or hosting disruptions, allowing threat actors to maintain command and control without interruption.

Lowered Barrier to Entry for Cybercrime

The widespread availability of Chinese open-source AI tools has significantly reduced the technical expertise required for cybercrime. This accessibility enables less-experienced attackers to launch complex cyberattacks, contributing to the reported 440% rise in BDD attacks. The tools allow a broader range of actors to utilize sophisticated attack methods.

How Blockchain Dead Drops Work

BDD typically involves storing either malware payloads or dynamic command-and-control (C2) configuration pointers on the blockchain. In C2 setups, the on-chain data directs compromised devices to the attacker's current infrastructure by providing domains, IP addresses, or other pointers. Malware on the victim's machine retrieves and decodes this data to connect to an off-chain C2 server for subsequent commands and malicious activity.

Payload Delivery and Off-Chain Execution

In payload-delivery setups, attackers store malicious code or encrypted payload components directly on-chain for victim machines to retrieve and execute. Once the necessary data is acquired, the operation moves off-chain, where the attacker executes the actual compromise. This can involve deploying infostealers targeting crypto wallets and credentials, or remote access trojans for persistent system control.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Blockchain-assisted cyberattacks, known as Blockchain Dead Drops (BDD), have increased over fivefold in the past year, primarily due to Iranian, North Korean, and Russian-linked groups. This technique stores malicious payloads or command-and-control configurations on public blockchains, making cyberattack campaigns more resilient to takedowns. The rise is partly attributed to the accessibility of open-source AI tools, lowering the technical barrier for less-experienced attackers.