DeadLock Ransomware Leverages Blockchain to Evade Law Enforcement Takedowns

The DeadLock ransomware operation is employing blockchain-backed infrastructure to shield its communications and data-leak operations from law enforcement takedowns. Since emerging in mid-2025, the group uses double-extortion tactics and has already listed 80 organizations on its leak site, primarily targeting European companies across sectors like IT, mining, manufacturing, and transportation.

Microsoft researchers find that DeadLock stores configuration data and leak site posts on the Polygon blockchain, allowing the malware to retrieve command-and-control addresses through smart contract queries. The operators also use the decentralized Session network for encrypted victim communications and host stolen files on Wasabi cloud services, reducing reliance on traditional domains that authorities can seize.

While the approach significantly increases resilience, Microsoft notes it is not completely foolproof. The system still depends on custom proxies, publicly accessible Polygon endpoints, and cloud-hosted files that can be removed. DeadLock's encryption scheme targets non-system directories with unique per-file keys and deliberately avoids systems in Russia, CIS nations, Iran, Syria, Oman, and Yemen.

Read More at the original source →