to leave a comment.

▲ Lazarus, North Korean hackers, virtual asset hacking/AI-generated image
On-chain security threats have rapidly escalated as state-backed hacker groups, including those from North Korea and Iran, have significantly increased their methods of hiding malware commands on public blockchains.
According to Cointelegraph, a cryptocurrency specialized media outlet, on September 18 (local time), blockchain analytics firm Chainalysis announced that instances of malware commands or infrastructure information being recorded on public blockchains have surged by 420% over the past 12 months. It was analyzed that state-affiliated hacker groups led approximately two-thirds of new attack activities occurring each quarter. This is an example of exploiting the immutability of blockchain, where data stored on a distributed ledger cannot be deleted even if servers or domains are seized by investigative authorities.
UNC5342, a North Korean-affiliated hacker group tracked by Google Threat Intelligence, cross-utilized multiple networks including Tron (TRX), Aptos (APT), and BNB Chain. They employed a sophisticated method of embedding encoded pointers in Tron and Aptos transactions to guide infected devices to the BNB Chain, then downloading encrypted server addresses and configuration data to attempt remote control and data theft. A hacker group believed to be linked to Iranian intelligence also exploited the system by sending small amounts to a wallet address associated with Satoshi Nakamoto, the founder of Bitcoin (BTC), to permanently store command and control routing data.
The potential misuse of artificial intelligence (AI) technology has been identified as a factor behind the rapid expansion of attack scale. Chainalysis stated that on-chain malware recording activities surged by 440% since open-source large AI models became available for generating malicious code. Eric Jardine, Head of Cybercrime Research at Chainalysis, pointed out a clear temporal correlation, explaining the possibility that generative AI tools have accelerated the rate at which hackers create malicious transactions.
Regulatory and exchange environment changes in the Asian region have also accelerated. With the strengthening of regulatory licensing standards by the Hong Kong Securities and Futures Commission (SFC), some exchanges, including CoinEx, have begun business restructuring, completely suspending local service operations. Market experts emphasize the urgent need for on-chain monitoring cooperation against state-level cyberattacks, alongside efforts by various governments to integrate into the institutional framework.
[Article Key Summary]
-Chainalysis' investigation revealed a 420% surge in activities hiding malware commands on blockchains over the past year.
-North Korean and Iranian-affiliated hacker groups exploited the immutability of Tron, Aptos, and Bitcoin networks to build attack infrastructure.
-Amid a 440% increase in malicious recordings due to AI model abuse, the Asian regulatory environment is also rapidly changing, including CoinEx's withdrawal.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.