DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
AI Summary
The DeadLock ransomware group has adopted a resilient, decentralized infrastructure leveraging Polygon blockchain smart contracts to manage victim communications and data leak operations, making takedown efforts more difficult. The ransomware encrypts files with the '.dlock' extension, uses hybrid encryption (Curve25519 and XChaCha20), and drops an HTML-based interactive recovery note (RECOVERY_CHAT.<UID>.html) that enables end-to-end encrypted chat and access to a blockchain-hosted data leak blog. The HTML note retrieves proxy server addresses via JavaScript interacting with Polygon smart contracts, allowing for censorship-resistant communication. The attackers also use geofencing to avoid certain regions, employ resource throttling, erase logs, and leverage AnyDesk for remote access.
AI-extracted · verify before operational use