Chainalysis Warns Malware Operators Are Turning Blockchains Into Dead Drops

5 days ago 7



TL;DR Chainalysis says cyber attackers are increasingly storing malware instructions on public blockchains. It calls the technique “Blockchain Dead Drops.” The blockchain itself is not compromised; attackers are using its public, persistent data layer. Cybercriminals have found a new use for public blockchains, and it has nothing to do with moving money. Chainalysis says a growing number of threat actors are storing command-and-control information for malware directly on-chain, creating what the analytics firm calls Blockchain Dead Drops, or BDDs. The idea is clever in an unpleasant sort of way. Traditional malware often relies on a server or domain to tell infected machines what to do next. Security teams can block the domain, seize the server or disrupt the infrastructure. A public blockchain is considerably harder to take offline. Attackers can place configuration data, addresses or pointers inside transactions or smart contract state and then instruct malware to read that information directly from the chain. The Blockchain Becomes The Noticeboard Chainalysis describes the wider technique as EtherHiding. Instead of compromising a blockchain protocol, attackers are effectively us...

Read Entire Article