DeadLock ransomware is making it harder for authorities and security teams to disrupt its operations by moving key parts of its infrastructure onto decentralized services. The group uses Polygon blockchain smart contracts, encrypted messaging and cloud storage to keep communicating with victims and publishing stolen data.

DeadLock uses blockchain-backed infrastructure

DeadLock ransomware emerged in mid-2025 and uses a double-extortion model. The attackers steal data, encrypt files and threaten to publish the stolen information unless victims pay.

By July 2026, the group’s leak site had listed 80 organisations, most of them in Europe. Its victims span IT, mining, transport, manufacturing, hospitality and consumer goods.

Researchers have also linked the malware’s deployment to several groups. One affiliate had previously operated in the Lynx and INC ransomware ecosystems.

The operation has now adopted a more resilient infrastructure model. DeadLock ransomware uses the Polygon blockchain to store configuration details and posts for its leak site. This reduces the group’s reliance on conventional domains and centralised web servers.

Smart contracts provide the active chat address

DeadLock does not rely on a fixed Tor address for victim negotiations. Instead, its HTML chat application queries a Polygon smart contract through a read-only blockchain request.

The contract returns the current address of the chat proxy. Therefore, the operators can move their victim communication service without changing the application shown to victims.

The group also uses the decentralised Session network to encrypt communications. It hosts stolen files through Wasabi cloud storage, giving victims access to data that the attackers claim to have taken.

This setup can complicate disruption efforts. A domain seizure or server takedown may not be enough to shut down every part of the operation. However, DeadLock ransomware is not completely immune to interference.

Its chat system still depends on a custom proxy, while Polygon RPC endpoints must remain available. In addition, cloud-hosted stolen files can still be removed by the hosting provider.

The malware encrypts files while limiting resource use

The DeadLock ransomware encryptor targets Windows systems. It is configured to avoid systems in former Soviet Union and CIS countries, as well as Iran, Syria, Oman and Yemen.

Before encryption begins, the malware deletes backups, stops virtualisation services and empties the Recycle Bin. It then encrypts selected non-system directories.

Each file is encrypted with a unique XChaCha20 key. The malware protects those keys with Curve25519 cryptography. For larger files, it encrypts intermittent 512-byte blocks to work faster while leaving the data largely unrecoverable.

DeadLock ransomware limits itself to 29% of available system memory and 70% of CPU resources. As a result, affected devices may remain usable during the attack, reducing the chance that users immediately notice the encryption activity.

The malware then adds a victim-specific identifier and the .dlock extension to encrypted files. It also changes file icons, drops TXT ransom notes and replaces the desktop wallpaper with a lock message.

Attackers demand Bitcoin or Monero payments

The group demands payment in Bitcoin or Monero. In exchange, it promises to provide a decryptor, delete the stolen data and disclose how it gained initial access. The attackers also offer security recommendations to affected organisations.

Microsoft recommends layered endpoint protection against DeadLock ransomware. Organisations should enable cloud-delivered antivirus protection, EDR in block mode, tamper protection and automated investigation and remediation.

Companies should also use Controlled Folder Access to restrict unauthorised file changes. Attack-surface reduction rules can block untrusted executables and reduce lateral movement through tools such as PsExec and WMI.


0 responses to “DeadLock ransomware uses blockchain to resist infrastructure takedowns”