Microsoft Exposes DeadLock’s Blockchain-Powered Ransomware Setup
DeadLock ransomware is using blockchain and decentralized services to make its infrastructure harder for law enforcement to disrupt.
Microsoft says the operation had listed around 80 victims by July 2026, mostly European organizations across IT, mining, transportation, manufacturing, hospitality, and consumer goods.
DeadLock ransomware stores data on Polygon
According to Microsoft’s analysis of DeadLock ransomware, the group uses the Polygon blockchain to store configuration data and content tied to its leak site.
Its victim-facing application can query a Polygon smart contract to obtain the current chat-proxy address. Attackers can therefore switch communication infrastructure without updating the application already delivered to victims.
This design reduces DeadLock’s dependence on traditional domains and servers that authorities could seize.
Session and Wasabi support the operation
DeadLock also uses the decentralized Session network for encrypted victim communications.
Attackers make stolen data available through Wasabi cloud storage, while the operation continues to rely on a custom chat proxy and publicly accessible Polygon RPC endpoints.
Microsoft says the architecture makes DeadLock more resilient, but it does not make the operation impossible to disrupt.
DeadLock keeps infected systems usable during encryption
Before encrypting files, DeadLock deletes backups, stops virtualization-related processes, and empties the Recycle Bin.
The Rust-based ransomware encrypts selected non-system directories with individual XChaCha20 keys. It also limits itself to roughly 29% of system memory and 70% of CPU resources, helping infected machines remain usable while encryption continues.
Encrypted files receive a victim-specific identifier and the .dlock extension. DeadLock also changes file icons, creates ransom notes, and replaces the desktop wallpaper.
Attackers demand Bitcoin or Monero
DeadLock accepts ransom payments in Bitcoin or Monero.
In return, operators promise a decryptor, deletion of stolen data, information about the initial breach, and security recommendations intended to prevent another intrusion.
Microsoft recommends cloud-delivered antivirus protection, endpoint detection and response in block mode, tamper protection, automated remediation, Controlled Folder Access, and attack-surface reduction rules.
Organizations should also restrict lateral movement through tools such as PsExec and WMI.
In other security news, CISA confirmed that a SharePoint flaw is being used in ransomware attacks, while Microsoft has also warned about StormEncryptor ransomware.
Microsoft also fixed around 400 flaws during the August 2026 Patch Tuesday.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages