
The DeadLock ransomware operation is utilizing a decentralized infrastructure that depends on blockchain-backed companies to guard its communication with victims and data-leak exercise.
The risk actor emerged in mid-2025 and makes use of double-extortion ways (knowledge theft/leak and file encryption) to strain victims into paying a ransom.
By July this yr, DeadLock’s knowledge leak web site listed 80 organizations, principally from Europe. Victims embrace corporations within the IT, mining, transportation, manufacturing, hospitality, and client items sectors.
Microsoft researchers noticed the malware being deployed by a number of teams, together with an affiliate beforehand linked to the Lynx and INC ransomware ecosystems.
The DeadLock ransomware operators adopted a brand new strategy that makes use of the Polygon blockchain to retailer configuration knowledge and the posts on the leak web site.
As an alternative of utilizing a conventional Tor URL, the HTML web page retrieves the present chat-proxy tackle by querying a sensible contract on the Polygon blockchain via a read-only eth_call.

Supply: Microsoft
Retrieving command-and-control (C2) addresses stored on the blockchain is now a common tactic for cybercriminals, however it’s a uncommon incidence within the ransomware area.
Moreover, DeadLock makes use of the decentralized Session community to encrypt sufferer communications and supplies entry to stolen recordsdata hosted on the Wasabi cloud service.
All that permits the operators to exchange the chat proxy with out modifying the victim-facing software and reduces their dependence on standard domains and internet servers, which will be taken down by regulation enforcement businesses.
Nevertheless, Microsoft famous that communications nonetheless require the customized proxy, public Polygon RPC endpoints should stay accessible, and recordsdata hosted on Wasabi will be eliminated, so resistance to disruptions isn’t absolute.

Supply: Microsoft
DeadLock encryption scheme
Microsoft’s report additionally dives into DeadLock’s encryption system, which is configured to keep away from nations within the former Soviet Union and the Commonwealth of Unbiased States (CIS) area, in addition to Iran, Syria, Oman, and Yemen.
After getting ready the Home windows host by deleting backups, stopping virtualization, and emptying the Recycle Bin, the locker encrypts choose non-system directories utilizing distinctive per-file XChaCha20 keys protected with the Curve25519 elliptic curve.
The ransomware is configured to make use of as much as 29% of the out there system reminiscence and 70% of CPU assets, so the sufferer could proceed utilizing the machine throughout the encryption course of with out main efficiency hiccups.
Bigger recordsdata are intermittently encrypted utilizing 512-byte blocks to hurry up the method whereas nonetheless making them principally irrecoverable.
Encrypted knowledge is renamed with a victim-specific identifier and the ‘.dlock’ extension, the icons are modified, TXT ransom notes are dropped, and the desktop wallpaper is modified to point that the system has been locked.

Supply: Microsoft
The attacker requests ransom funds in Bitcoin or Monero in change for a decryptor, a promise to delete the stolen knowledge, particulars in regards to the preliminary entry vector, and a set of safety suggestions.
To defend towards DeadLock ransomware assaults, Microsoft recommends strengthening endpoint defenses via cloud-delivered antivirus safety, EDR in block mode, tamper safety, automated investigation and remediation, and automated assault disruption.
Organizations also needs to limit unauthorized file adjustments utilizing Managed Folder Entry and allow attack-surface discount guidelines to dam untrusted executables and lateral motion by way of PsExec and WMI.
General prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

