The ransomware group known as DeadLock has been observed utilizing decentralized infrastructure to enhance victim communications and data leak operations, thereby improving operational resilience. According to reporting by The Hacker News, the group employs a recovery ecosystem that integrates the Session messaging network with blockchain-backed services for resource management during extortion.
First detected in July 2025, DeadLock employs double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of now, the group has claimed 96 victims, primarily located in Italy, Spain, Poland, Türkiye, and the U.S. Notably, the group has maintained a lower profile compared to its peers, as it is not associated with any known affiliate programs and lacks a data leak site.
Technical Characteristics and Attack Methods
DeadLock attacks are characterized by the encryption of files with the “.dlock” extension, altering file icons, and changing the victim’s desktop wallpaper to display a ransom message. The ransomware employs a selective encryption model, excluding certain directories and file types, and utilizes a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher.
The ransom note instructs victims to download a decentralized messaging application called Session to negotiate payment in Bitcoin or Monero. Victims are also promised a “security report” detailing the attackers’ methods and assurances against future targeting upon payment.
Innovative Communication Infrastructure
One of the most distinctive features of DeadLock is its use of an HTML note (“RECOVERY_CHAT.
The HTML file employs JavaScript to interact with Polygon smart contracts for decentralized proxy server address rotation, creating a resilient infrastructure that can evade censorship and takedown efforts. This innovative approach poses significant challenges for law enforcement and disruption efforts, as it allows the operators to update proxy URLs without altering victim-facing domains.
Microsoft’s Threat Intelligence team noted that this infrastructure model represents a significant evolution in ransomware communication channels, enhancing the resilience of DeadLock’s operations and enabling continuity for victims despite potential disruption efforts.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


