链上攻击加速:国家支持的黑客成为链上恶意软件激增的主要推手
近期,Chainalysis 发布的新研究指出,公共区块链上的恶意软件活动正急剧上升。该机构报告显示,今年链上恶意软件数量激增了 420%,其中绝大多数增长归因于与国家有关联的黑客组织,特别是与朝鲜和伊朗相关的团体。
Chainalysis 还指出,公共区块链使得恶意活动具有异常强的韧性:即使域名、服务器或传统的代码托管服务被关停,存储在链上的数据仍可保持较长时间的可用性和可访问性。
核心要点
- 国家背景黑客主导激增: Chainalysis 将今年 420% 的链上恶意软件激增主要归咎于与国家有关联的黑客,尤其是那些与朝鲜和伊朗相关的势力。
- 占比显著: 在国家支持的活动涉及的攻击者发布恶意软件指令或基础设施细节的新案例中,此类活动约占三分之二。
- 特定团伙识别: Chainalysis 确认了与朝鲜有关联的组织 UNC5342,并将其与此前未归属的活动联系起来,这些活动横跨 Tron、Aptos 和 BNB Smart Chain 等多个生态系统。
- 延长恶意软件“生命周期”:公共区块链通过保留命令与控制(C2)或有效载荷相关指令,在链下基础设施被移除后,延长了恶意软件的存活时间。
国家支持的活动驱动链上恶意软件飙升
Chainalysis 的报告重点分析了攻击者如何越来越多地利用公共区块链,不仅用于转移资金,还用于存储恶意指令和支持性基础设施信息。据该机构称,这导致今年链上可见的恶意软件操作量显著增加——增幅达 420%,且大部分增长由国家支持的行动者造成。
分析强调,国家支持的黑客约占新链上恶意软件活动的三分之二。从实际角度来看,这表明最复杂且持久的恶意活动正越来越深地融入基于区块链的执行和数据存储中,而不再仅仅依赖容易遭到破坏的传统基础设施。
Chainalysis 进一步指出了与朝鲜有关的组织 UNC5342,将其与之前跨多个生态系统(包括 Tron、Aptos 和 BNB Smart Chain)的未归属活动联系起来。对于投资者和开发者而言,跨链归因至关重要,因为它意味着战术和工具在网络间的复用,而非局限于单一平台的孤立事件。
为何公共区块链使恶意软件更难消除
Chainalysis 的一个重要论点是,链上存储改变了恶意软件的运营经济学。与典型的恶意软件基础设施不同——在后者中,一次下架行动可以切断对有效载荷代码、托管服务或指令的访问——记录在公共账本上的信息即使在外部组件被移除后仍可访问。
Chainalysis 解释说,这种持久性可以延长恶意软件活动的寿命。如果攻击者将指令或基础设施相关数据存储在上链环境中,防御者虽然可以关闭服务器或域名,但根据恶意软件的设计方式,底层的链上信息仍可能被检索和利用。
报告将此与早些时候归因于朝鲜黑客的行为进行了比较。据报道,在 2025 年,这些行动者使用了一种称为“EtherHiding”的技术,将窃取加密货币的代码植入智能合约中——再次利用了智能合约部署一旦上线便难以“撤销”的特性。
跨链归因信号更广泛的威胁工具集
Chainalysis 在 Tron、Aptos 和 BNB Smart Chain 上识别出 UNC5342,强调了安全团队日益观察到的一个趋势:攻击者将各条公链视为分发、执行或存储恶意组件的可互换环境。
For users, this means that the risk of malware on the chain is not limited to vulnerabilities in individual networks. For exchanges, custody providers, and wallet developers, this requires not only monitoring known malicious contracts or addresses, but also focusing on patterns of how malicious instructions are encoded, delivered, and referenced-especially when these "instructions" are stored directly on the chain.
Although Chainalysis's findings show a strong element of national support, the broader message is that attackers can scale up by turning to platforms where they can leverage previous experience or infrastructure to adapt with minimal modifications.
Concerns for future on-chain defense
As Chainalysis reports that more state-backed actors are adopting on-chain approaches, the current focus of the market should be on faster detection of on-chain malware patterns and establishing stricter controls on smart contract interactions, data indexing, and on-chain malicious command monitoring.
All parties should be looking to see whether this 420% increase will continue in subsequent reports, and whether security companies will further narrow the attribution to specific groups and technologies-particularly those that allow malware logic to remain usable after an off-chain element is interrupted.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
APT
BNB
ETH
TRX