DeadLock Ransomware Leverages Polygon Smart Contracts for Enhanced Extortion Resilience

Published:

spot_img

The ransomware group known as DeadLock has been observed utilizing decentralized infrastructure to enhance victim communications and data leak operations, thereby improving operational resilience. According to reporting by The Hacker News, the group employs a recovery ecosystem that integrates the Session messaging network with blockchain-backed services for resource management during extortion.

First detected in July 2025, DeadLock employs double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of now, the group has claimed 96 victims, primarily located in Italy, Spain, Poland, Türkiye, and the U.S. Notably, the group has maintained a lower profile compared to its peers, as it is not associated with any known affiliate programs and lacks a data leak site.

Technical Characteristics and Attack Methods

DeadLock attacks are characterized by the encryption of files with the “.dlock” extension, altering file icons, and changing the victim’s desktop wallpaper to display a ransom message. The ransomware employs a selective encryption model, excluding certain directories and file types, and utilizes a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher.

The ransom note instructs victims to download a decentralized messaging application called Session to negotiate payment in Bitcoin or Monero. Victims are also promised a “security report” detailing the attackers’ methods and assurances against future targeting upon payment.

Innovative Communication Infrastructure

One of the most distinctive features of DeadLock is its use of an HTML note (“RECOVERY_CHAT..html”) dropped in all drive root directories and Desktop folders. This HTML note functions as an interactive web application, facilitating encrypted chat and access to a data leak blog hosted on the Polygon blockchain. This setup allows for direct communication between the operator and the victim without requiring traditional backend servers.

The HTML file employs JavaScript to interact with Polygon smart contracts for decentralized proxy server address rotation, creating a resilient infrastructure that can evade censorship and takedown efforts. This innovative approach poses significant challenges for law enforcement and disruption efforts, as it allows the operators to update proxy URLs without altering victim-facing domains.

Microsoft’s Threat Intelligence team noted that this infrastructure model represents a significant evolution in ransomware communication channels, enhancing the resilience of DeadLock’s operations and enabling continuity for victims despite potential disruption efforts.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign

Lazarus Group's Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign In early 2026, Check Point Research began tracking a significant wave of cyberattacks under...

FreePBX Security Advisory AV26-818 Warns of Vulnerabilities in Multiple Products

Advisory Number: AV26-818Date Issued: August 14, 2026 FreePBX has issued a security advisory regarding vulnerabilities affecting several of its products. As of August 13, 2026,...

Jaguar Land Rover Faces Sales Decline Amid Middle East Conflict and Cyber Attack Recovery Challenges

Jaguar Land Rover (JLR) is facing significant challenges in its recovery efforts following a cyber attack last year, compounded by ongoing geopolitical tensions in...

Threat Actors Exploit Microsoft SharePoint CVE-2026-55040 Authentication Bypass Following PoC Release

Threat actors are actively exploiting a newly disclosed vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the release of a proof-of-concept (PoC) code. This...