DeadLock Ransomware Leverages Polygon Blockchain for Unstoppable Extortion
DeadLock ransomware has been making headlines for its unique approach to extorting victims. First observed in July 2025, it had listed over 80 alleged victims on its leak site by July 2026, with more than half based in Europe.
The malware targets a wide range of sectors, including IT, mining, transport, manufacturing, hospitality, and consumer goods, across six continents. Microsoft analysts identified DeadLock as a Rust-based encryptor that pairs double extortion with unusually durable communications.
The operation's impact goes beyond inaccessible files. DeadLock deletes recovery material, targets backup, security, remote-access, and cloud-sync processes, clears event logging, and leaves victims with a browser-based recovery page.