bleeping-computer · Crawled Aug 11, 2026
DeadLock ransomware uses blockchain to resist infrastructure takedown
3 IoCs 2 Malware
Read original article ↗
AI Summary
The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 25 techniques
T1014 Rootkit · Defense Evasion T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1056.001 Keylogging · Collection T1070.001 Clear Windows Event Logs · Defense Evasion T1071.001 Web Protocols · Command And Control T1083 File and Directory Discovery · Discovery T1105 Ingress Tool Transfer · Command And Control T1213 Data from Information Repositories · Collection T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491.001 Internal Defacement · Impact T1566 Phishing · Initial Access T1059.001 PowerShell · Execution T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1203 Exploitation for Client Execution · Execution T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion T1542.001 System Firmware · Persistence T1543.003 Windows Service · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1552.001 Credentials In Files · Credential Access T1574.002 DLL Side-Loading · Persistence T1588.001 Malware · Resource Development