DeadLock ransomware uses blockchain to resist infrastructure takedown

DeadLock ransomware uses blockchain to resist infrastructure takedown
DeadLock ransomware uses a decentralized setup with the Polygon blockchain, Session, and Wasabi to hide communication, store leak-site data, and make takedowns harder. Microsoft says the operation, active since mid-2025, has hit 80 organizations across multiple sectors and relies on double extortion with a .dlock encryptor and ransom demands in Bitcoin or Monero. #DeadLock #Polygon #Session #Wasabi

Keypoints

  • DeadLock uses blockchain-backed services to manage victim communication and leak-site content.
  • The group relies on the Polygon blockchain instead of a traditional Tor-only setup.
  • Session encrypts victim chats, while Wasabi hosts stolen files for data leaks.
  • The ransomware has been used by multiple groups, including an affiliate tied to Lynx and INC.
  • Microsoft advises stronger endpoint defenses, Controlled Folder Access, and attack-surface reduction rules.

Read More: https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/