DeadLock Ransomware Leverages Polygon Smart Contracts to Evade Disruption
The DeadLock ransomware group has been observed using decentralized infrastructure to facilitate victim communications and data leak operations. This is an attempt by the group to improve operational resilience.
Microsoft's Threat Intelligence team noted that the recovery ecosystem of DeadLock combines Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.
As of this month, the group has claimed 96 victims, primarily located in Italy, Spain, Poland, Türkiye, and the U.S. The attacks by the group are known to encrypt files with the '.dlock' extension and modify the victim's wallpaper to display a ransom note.
The ransomware employs a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption.