Hackers claim breach of Russian election systems days before State Duma vote
Days before Russia’s State Duma elections, the anonymous hacker group CikLeak said it had breached the infrastructure of Russia’s Central Election Commission and its contractors, according to a statement from the group.
According to a Chainalysis report, state-linked hackers have seen a staggering 420% increase in storing malware infrastructure and instructions on public blockchains over the past year. The surge is particularly concerning as state actors from North Korea and Iran are among those adopting this technique. North Korea-linked hackers, in particular, have been found using Tron, Aptos, and BNB Chain to maintain their malware infrastructure.
The report connected previously unattributed activity spanning these blockchain networks to a North Korean hacking group tracked by Google Threat Intelligence known as UNC5342.
The report highlights the durability of malware campaigns facilitated by public blockchains. Once stored, the information remains accessible even after domains, servers, or code repositories are taken down. In 2025, North Korean hackers employed a technique called EtherHiding to conceal crypto-stealing code within smart contracts on the Ethereum blockchain.
Chainalysis also identified Iran-linked actors embedding encoded command-and-control routing data onto the Bitcoin blockchain, believed to be linked to Iran's Ministry of Intelligence. The attackers used attacker-controlled wallets to send small payments to a well-known Bitcoin address, which served as a location for infected devices to check for updated directions.
By changing their server infrastructure through new Bitcoin transactions, the malware could adapt and move offchain for activities like remote access and credential theft.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- State hackers drive 420% surge in onchain malware, Chainalysis finds cointelegraph.com