North Korea drives onchain malware surge, CoinEx shuts: Asia Express
The article reports that North Korea and Iran account for most onchain malware activity. It also notes that CoinEx has shut down and that Malaysia is among the most crypto-curious Islamic nations.
Cointelegraph by Andrew Fenton
Publisher Cointelegraph
Sep 17, 2026 at 11:49 PM UTC · 5 Min. Lesezeit

Kernpunkte
- North Korea and Iran are identified as the main sources of onchain malware.
- CoinEx has shut down, according to the article headline.
- Malaysia is named among the most crypto-curious Islamic nations.
North Korean and Iran linked hackers were responsible for the majority of the 420% increase this year in malware on public blockchains according to a Chainalysis report.
State-linked hackers accounted for roughly two-thirds of new activity whereby attackers stored malware instructions or infrastructure information on public blockchains.
Chainalysis also identified UNC5342, a North Korea linked group, to previously unattributed activity spanning Tron, Aptos and BNB Smart Chain.
Chainalysis said using public blockchains increases the durability of malware campaigns because the stored information remains accessible after domains, servers or code repositories are taken down. In 2025, North Korean hackers used a similar technique called EtherHiding to place crypto-stealing code in smart contracts.
North Korea using foreign talent to help infiltrate US companies: Report
North Korea (DPRK) is now using remote workers from third countries, including Iran and Lebanon, to pass job interviews, after which the positions are taken over by North Korean operatives. The aim is infiltrate US companies and obtain money to fund its weapons programs, NBC reported.
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
