DeadLock Ransomware Leverages Blockchain for Resilience
The DeadLock ransomware operation has been using blockchain-backed services to protect its communication with victims and data-leak activity.
Microsoft researchers observed that DeadLock's data leak site listed 80 organizations, mostly from Europe, by July this year. The affected companies are in various sectors, including IT, mining, transportation, manufacturing, hospitality, and consumer goods.
The threat actor uses double-extortion tactics (data theft/leak and file encryption) to pressure victims into paying a ransom. DeadLock's operators adopted a new approach that uses the Polygon blockchain to store configuration data and posts on the leak site.