๐Ÿ“… Friday, 18 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Korea Utara Tanam Malware di Tron dan Aptos - Aktivitas Kejahatan On-Chain Naik 420% Setahun Terakhir

North Korean Hackers Plant Malware on Tron and Aptos - On-Chain Cybercrime Surges 420% in Past Year

A recent Chainalysis report revealed that the number of attackers embedding malware instructions or infrastructure data into public blockchains jumped 420% over the past 12 months.

State-sponsored hackers dominate the trend, accounting for roughly two-thirds of all new activity each quarter. Citing tracking from Google Threat Intelligence, Chainalysis identified a North Korean group dubbed UNC5342 alongside Iranian-affiliated hackers as key actors behind the spike.

Leveraging Public Networks as Safe Havens

The primary motive for hackers shifting to blockchains is operational resilience. Unlike centralized systems, data written to a blockchain remains readable and accessible to malicious programs even if authorities seize their domains, origin servers, or code repositories.

North Korea’s UNC5342 group engineered a multi-layered path to compromise victim devices. They placed encrypted pointers within Tron transactions as a primary route and set up the Aptos network as a backup staging relay. Both network pointers serve to direct infected devices to a single Binance Smart Chain (BSC) transaction.

The BSC transaction stores encrypted server addresses alongside full hacker configuration data. This sequence of on-chain instructions connects victim machines to off-chain infrastructure to grant remote access and exfiltrate data. Iranian hackers took a more streamlined approach, embedding command instructions directly into Bitcoin transaction records.

Timing Correlation with New AI Models

Chainalysis recorded a 440% increase in malicious code writing activity since July 2025. This surge coincided with the release of an open-source Chinese artificial intelligence model capable of generating exploit code with minimal safety guardrails.

Chainalysis cybercrime research lead Eric Jardine highlighted a clear temporal correlation between the AI model’s availability and the curve in hacker activity. Although a direct causal link has not been conclusively proven, exploit activity surged during the exact same month.

Embedding code on public ledgers builds upon past exploitation maneuvers. In 2025, North Korean hackers had already experimented with a technique dubbed EtherHiding - a method of placing crypto-stealing code directly inside smart contracts.

Public blockchain networks with thousands of nodes now indiscriminately serve two groups: investors transferring funds and hackers hosting their cyber toolkits. Reported by Cointelegraph.

Read also: Celsius Sues BitMEX for $495M - Claims 6,360 BTC Seized During 2020 COVID Crash


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share