Blockchain-assisted cyberattacks surge fivefold, driven by Iranian and North Korean state actors, Russia-linked groups
- ID
- 29874
- Status
- summarized
- Published
- 29 Sep 2026, 10:10 PM
- Fetched
- 29 Sep 2026, 11:59 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cyber-security/blockchain-assisted-cyberattacks-surge-fivefold-driven-by-iranian-and-north-korean-state-actors-russia-linked-groups-open-weight-llms-are-linked-to-an-increase-in-attacks
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 3.0
- Created
- 29 Sep 2026, 11:59 PM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Tom's Hardware reports on a Chainalysis report finding blockchain-assisted cyberattacks up more than fivefold since last year, driven mainly by North Korean and Iranian state actors and Russian-speaking criminal groups. The technique, called Blockchain Dead Drops (BDD), stores malicious payloads in on-chain transactions and smart contracts so infected devices can retrieve them on demand from public, censorship-immune blockchains rather than from servers that can be seized or blocked. The excerpt also claims open-weight LLMs are linked to an increase in attacks, but cuts off mid-sentence before any supporting detail.
Why it matters
The concrete operational change named here is payload hosting moving off takedown-able servers onto public chains, which means incident response that relies on blocking domains, IPs, or seizing C2 infrastructure may not remove the payload source. If your detection stack only watches HTTP/DNS egress, BDD retrieval traffic is a different channel you have not instrumented. Note that the open-weight LLM claim is asserted in the headline but the excerpt ends before showing the evidence, so do not repeat it as fact.
Discussion angle
Ask whether anyone's egress monitoring or blocklists would actually catch a payload fetched from a blockchain RPC endpoint, and whether adding that traffic to watchlists is worth the noise versus relying on endpoint detection instead.