Chainalysis has identified a technique called Blockchain Dead Drops by which cyber attackers store malware instructions directly on public blockchains. Malicious activity has increased by about 440% since mid-2025. This technique, dubbed EtherHiding, exploits blockchain data persistence to control malware without relying on conventional servers. The groups involved are associated with North Korea, Iran and Russian-language cybercrime operations. The blockchain itself is not compromised; attackers are simply using a deliberately designed feature: the public, permanent data layer.
Source: Read the original article

