DeadLock ransomware uses a decentralized setup with the Polygon blockchain, Session, and Wasabi to hide communication, store leak-site data, and make takedowns harder. Microsoft says the operation, active since mid-2025, has hit 80 organizations across multiple sectors and relies on double extortion with a .dlock encryptor and ransom demands in Bitcoin or Monero. #DeadLock #Polygon #Session #Wasabi
Keypoints
- DeadLock uses blockchain-backed services to manage victim communication and leak-site content.
- The group relies on the Polygon blockchain instead of a traditional Tor-only setup.
- Session encrypts victim chats, while Wasabi hosts stolen files for data leaks.
- The ransomware has been used by multiple groups, including an affiliate tied to Lynx and INC.
- Microsoft advises stronger endpoint defenses, Controlled Folder Access, and attack-surface reduction rules.