DeadLock ransomware op uses blockchain to hide its operations

 

DeadLock ransomware op uses blockchain to hide its operations

The DeadLock ransomware group is using blockchain and other decentralized services to make its operations harder to disrupt.

DeadLock, which was first spotted in mid-2025, uses double-extortion tactics, stealing data and encrypting files before demanding a ransom. By July 2026, the group's leak site had listed 80 victims, mainly in Europe, across industries including IT, mining, transportation, manufacturing, hospitality, and consumer goods.

Microsoft researchers found that DeadLock uses the Polygon blockchain to store configuration data and information used by its leak site. Instead of a fixed Tor address, the site can use a smart contract to find the current address of its chat proxy, allowing attackers to change the proxy without updating the software used by victims.

The group also uses the decentralized Session network for victim communications and Wasabi cloud storage to host stolen files. The tactic helps to minimize dependence on traditional websites and servers that could be taken down by law enforcement. However, DeadLock still relies on its custom proxy, public Polygon access points, and cloud-hosted stolen files.

The ransomware also uses strong encryption and can consume up to 70% of CPU resources and 29% of available memory. It encrypts selected files with XChaCha20 and Curve25519, renames them with the .dlock extension, and leaves ransom notes on infected systems. Attackers demand payment in Bitcoin or Monero.

To minimize the risk of attacks, organizations are advised to implement stronger endpoint protection, including cloud antivirus, EDR, tamper protection, Controlled Folder Access, and attack-surface reduction rules to limit ransomware activity and prevent lateral movement.


Back to the list