Join our Newsletter — 33% off our NHI Course

Why does a state-backed group use cryptocurrency to fund operations instead of only to move money out of the system?

A state-backed group may use cryptocurrency to self-fund operations, obscure transaction trails, and support intelligence collection without relying on a single obvious financing channel. In practice, that means mining, extortion, wallet theft, and semi-legitimate services can all become part of the same financing pattern. The risk is not just theft, but operational persistence and harder attribution across multiple activity types.

Why state-backed groups treat cryptocurrency as an operational capability, not just an exit route

Cryptocurrency can function as a funding mechanism, a laundering layer, and a way to convert cyber activity into usable resources with fewer obvious banking touchpoints. For a state-backed group, that matters because the objective is often continuity: enough liquidity to keep operations moving, even when conventional financial channels are harder to use or easier to monitor.

That makes crypto useful beyond “cash-out.” It can support recurring costs, reimburse operators, pay for infrastructure, and create a parallel economic path that is harder to disrupt than a single theft-and-transfer event.

How the financing pattern broadens the group’s operating model

Once cryptocurrency is part of the operating model, the group is no longer limited to one type of monetisation. Mining can generate direct holdings, extortion can create pressure to pay, wallet theft can convert compromise into liquid value, and semi-legitimate services can blur the boundary between criminal and commercial activity.

This mix matters because it reduces dependence on any one revenue stream. If one channel is disrupted, the group can shift to another without changing the underlying tradecraft, which makes the campaign more resilient and less predictable for defenders.

That resilience is one reason CISA cyber threat advisories remain useful for tracking how threat actors move between access, exploitation, and monetisation patterns across campaigns.

Why attribution and disruption become harder when money, access, and tradecraft overlap

Crypto use can also complicate attribution because the same actor may be visible through different behaviours at different times: mining on one system, extorting another target, moving stolen value through wallets, and buying services through intermediaries. That creates a fragmented picture unless investigators correlate infrastructure, wallet activity, and operational behaviour together.

The main defensive challenge is that financial activity may be distributed across many small events rather than one large transfer. Investigators therefore need to treat funding as part of the attack chain, not a separate accounting problem.

For practitioners mapping those chains, the MITRE ATT&CK Enterprise Matrix is helpful for connecting credential access, persistence, privilege escalation, and lateral movement to downstream monetisation.

Risk and Threat Considerations

Crypto-funded operations are harder to suppress because the group can keep generating value after a single compromise is contained, and the same wallet or service flow may support several operational goals at once. The risk is not only theft of funds, but longer-lived activity, more durable infrastructure, and weaker attribution across separate incidents.

Failure mechanism: A threat actor combines multiple monetisation paths, such as mining, extortion, wallet theft, and service provision, so that disruption of one revenue stream does not stop the campaign.

Impact: Defenders face a broader attack surface, slower containment, and a harder investigation because financial activity becomes interwoven with intrusion, persistence, and exfiltration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK TA0011 — Command and Scripting Interpreter Covers the operational intrusion chain that funds later monetisation steps.
TA0003 — Persistence Persistent access is what enables recurring theft, mining, or extortion monetisation.
TA0006 — Credential Access Wallet theft and account abuse often depend on credential or secret compromise.
Recommendation — Map observed intrusion stages to ATT&CK and hunt for monetisation-linked activity. Hunt for persistence mechanisms that keep revenue-generating access alive. Prioritise detection of credential theft that can convert access into funds.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy The topic requires treating financial monetisation as an operational risk to the campaign.
Recommendation — Include monetisation pathways in risk assessments and threat models.

Practitioner Guidance

What to prioritise: Treat wallet activity, mining behaviour, extortion indicators, and service usage as linked signals, not separate cases. The useful question is whether the same operator is building a repeatable funding system that can survive enforcement pressure.

What to verify: Look for evidence that compromise is being converted into operational liquidity, such as reused infrastructure, repeated wallet touchpoints, or consistent transfer patterns across incidents. If those patterns exist, the case is larger than a one-off theft.

Practitioner takeaway: The key judgement is whether cryptocurrency is being used to fund persistence, not merely to move proceeds, because that changes how quickly the activity can reconstitute after disruption.