DeadLock Ransomware Leverages Polygon Smart Contracts for Enhanced Extortion Resilience

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The ransomware group known as DeadLock has been observed utilizing decentralized infrastructure to enhance victim communications and data leak operations, thereby improving operational resilience. According to reporting by The Hacker News, the group employs a recovery ecosystem that integrates the Session messaging network with blockchain-backed services for resource management during extortion.

First detected in July 2025, DeadLock employs double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of now, the group has claimed 96 victims, primarily located in Italy, Spain, Poland, Türkiye, and the U.S. Notably, the group has maintained a lower profile compared to its peers, as it is not associated with any known affiliate programs and lacks a data leak site.

Technical Characteristics and Attack Methods

DeadLock attacks are characterized by the encryption of files with the “.dlock” extension, altering file icons, and changing the victim’s desktop wallpaper to display a ransom message. The ransomware employs a selective encryption model, excluding certain directories and file types, and utilizes a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher.

The ransom note instructs victims to download a decentralized messaging application called Session to negotiate payment in Bitcoin or Monero. Victims are also promised a “security report” detailing the attackers’ methods and assurances against future targeting upon payment.

Innovative Communication Infrastructure

One of the most distinctive features of DeadLock is its use of an HTML note (“RECOVERY_CHAT..html”) dropped in all drive root directories and Desktop folders. This HTML note functions as an interactive web application, facilitating encrypted chat and access to a data leak blog hosted on the Polygon blockchain. This setup allows for direct communication between the operator and the victim without requiring traditional backend servers.

The HTML file employs JavaScript to interact with Polygon smart contracts for decentralized proxy server address rotation, creating a resilient infrastructure that can evade censorship and takedown efforts. This innovative approach poses significant challenges for law enforcement and disruption efforts, as it allows the operators to update proxy URLs without altering victim-facing domains.

Microsoft’s Threat Intelligence team noted that this infrastructure model represents a significant evolution in ransomware communication channels, enhancing the resilience of DeadLock’s operations and enabling continuity for victims despite potential disruption efforts.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....