North Korea drives onchain malware surge, CoinEx shuts: Asia Express

A Chainalysis report found a 420% year-to-date increase in malware activity recorded on public blockchains, driven largely by groups linked to North Korea and Iran. Separately, Hong Kong-founded crypto exchange CoinEx said it will cease operations after nine years, citing low trading volumes, liquidity issues and rising regulatory costs.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 5 hours agoUpdated about 1 hour ago0 views
North Korea drives onchain malware surge, CoinEx shuts: Asia Express

Why It Matters

The rise in onchain malware highlights a shift by state-linked attackers to leverage public ledgers for resilient malware infrastructure, raising new security and enforcement challenges for blockchain ecosystems. CoinEx’s closure reflects persistent business and regulatory pressures in the crypto exchange sector amid a prolonged bear market.

Key Facts

  • Increase in onchain malware: 420% year-to-date, according to Chainalysis
  • Share of new activity by state-linked actors: Roughly two-thirds of new onchain malware activity attributed to state-linked hackers
  • Named threat group: UNC5342, linked to North Korea, tied to activity on Tron, Aptos and BNB Smart Chain
  • Notable technique: Use of public blockchains to store malware instructions or infrastructure information; example cited: EtherHiding in 2025
  • CoinEx closure: CoinEx to cease operations after 9 years; withdrawals open until Dec. 22

A Chainalysis analysis identified a sharp uptick in malware activity placed on public blockchains, reporting a 420% increase year-to-date. The firm said state-linked hacker groups, particularly those associated with North Korea and Iran, were responsible for the majority of that rise, with roughly two-thirds of newly observed campaigns involving actors tied to national intelligence services.

Chainalysis noted that attackers are increasingly embedding malware instructions or infrastructure details directly on public ledgers. This approach makes malicious campaigns more durable because information stored on-chain remains accessible even after domains, servers or code repositories are taken down. The firm also attributed previously unattributed activity on Tron, Aptos and BNB Smart Chain to UNC5342, a group linked to North Korea, and cited a 2025 tactic called EtherHiding used by North Korean actors to conceal crypto-stealing code in smart contracts.

In separate reporting on state-linked operations, NBC said North Korea has used remote workers from third countries, including Iran and Lebanon, to pass job interviews and then replace those hires with DPRK operatives to infiltrate U.S. companies and raise funds. Chainalysis’ findings about onchain persistence of malware underscore the evolving operational tradecraft being deployed by these actors.

Also in the region, CoinEx — a crypto exchange founded in Hong Kong — announced it will shut down after nine years in business. The company cited falling trading volumes and liquidity during the bear market, along with rising regulatory and compliance costs, as reasons for the decision. CoinEx said customers could continue to withdraw funds until Dec. 22.

Keep Reading