Malware
Lynx
According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.
Indicators of Compromise 7
MITRE ATT&CK TTPs 13
T1014 T1021.006 T1027 T1056.001 T1070.001 T1071.001 T1083 T1105 T1213 T1486 T1490 T1491.001 T1566
Rootkit
Defense Evasion
Windows Remote Management
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
Clear Windows Event Logs
Defense Evasion
Web Protocols
Command And Control
File and Directory Discovery
Discovery
Ingress Tool Transfer
Command And Control
Data from Information Repositories
Collection
Data Encrypted for Impact
Impact
Inhibit System Recovery
Impact
Internal Defacement
Impact
Phishing
Initial Access
Source Articles
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.
bleeping-computer ·1h ago
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware group has adopted a resilient, decentralized infrastructure leveraging Polygon blockchain smart contracts to manage victim communications and data leak operations, making takedown efforts more difficult. The ransomware encrypts files with the '.dlock' extension, uses hybrid encryption (Curve25519 and XChaCha20), and drops an HTML-based interactive recovery note (RECOVERY_CHAT.<UID>.html) that enables end-to-end encrypted chat and access to a blockchain-hosted data leak blog. The HTML note retrieves proxy server addresses via JavaScript interacting with Polygon smart contracts, allowing for censorship-resistant communication. The attackers also use geofencing to avoid certain regions, employ resource throttling, erase logs, and leverage AnyDesk for remote access.
hacker-news ·7h ago