DeadLock ransomware uses a decentralized setup with the Polygon blockchain, the Session network, and Wasabi cloud storage to hide its communication and data-leak operations. Microsoft says the group, active since mid-2025, has already listed 80 victims and relies on double extortion to pressure organizations into paying. #DeadLock #Polygon #Session #Wasabi
Keypoints
- DeadLock is a ransomware operation that appeared in mid-2025.
- It uses double extortion by stealing data and encrypting files.
- The leak site had 80 organizations listed by July, mostly in Europe.
- DeadLock stores chat-proxy and leak-site data on the Polygon blockchain.
- Microsoft recommends stronger endpoint protection and attack-surface reduction controls.