DeadLock Ransomware Leverages Blockchain for Unprecedented Resilience
The DeadLock ransomware operation has been using blockchain technology to protect its communication and data-leak activities, making it harder for law enforcement agencies to disrupt their infrastructure. This decentralized approach involves storing configuration data on the Polygon blockchain and using a smart contract to retrieve command-and-control addresses.
The threat actor emerged in mid-2025 and uses double-extortion tactics to pressure victims into paying a ransom. By July this year, DeadLock's data leak site listed 80 organizations from various sectors, including IT, mining, transportation, manufacturing, hospitality, and consumer goods.
Microsoft researchers observed that the malware is being deployed by multiple groups, including an affiliate previously linked to the Lynx and INC ransomware ecosystems. The operators have configured DeadLock's encryption system to avoid countries in the former Soviet Union and the Commonwealth of Independent States (CIS) region, as well as Iran, Syria, Oman, and Yemen.
DeadLock's resilience is due to its use of a decentralized Session network to encrypt victim communications and provide access to stolen files hosted on the Wasabi cloud service. However, Microsoft notes that while this approach reduces dependence on conventional domains and web servers, it is not absolute resistance to disruptions.