bleeping-computer · Crawled Aug 11, 2026

DeadLock ransomware uses blockchain to resist infrastructure takedown

3 IoCs 2 Malware
Read original article ↗

AI Summary

The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain wasabi[.]com Details →
GitHub Repo sessionapp/session-android Details →
Package eth_call Details →

MITRE ATT&CK TTPs 25 techniques