DeadLock Ransomware Exploits Decentralized Infrastructure
The DeadLock ransomware group has been observed using decentralized infrastructure to facilitate victim communications and data leak operations. This includes combining Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.
According to Microsoft Threat Intelligence, multiple threat actors, including an affiliate for Lynx and INC ransomware, have deployed DeadLock. The group was first detected in July 2025, employing double extortion tactics to encrypt victim environments and threaten data release if a payment is not made.
The group has claimed 96 victims as of this month, mostly located in Italy, Spain, Poland, Türkiye, and the U.S. A notable aspect of DeadLock's operations is its use of Polygon smart contracts for decentralized proxy server address rotation, which increases the resilience of their communication infrastructure.