DeadLock Ransomware Operators Use Blockchain to Evade Takedown Efforts, Expose 80 Organizations
In a brazen display of cryptocurrency-fueled innovation, the DeadLock ransomware operation has leveraged blockchain technology to fortify its communication channels and data leak activities against disruption by law enforcement agencies. The threat actor, which emerged in mid-2025, employs double-extortion tactics – stealing sensitive data while encrypting files – to coerce victims into paying hefty ransoms.
At the time of writing, DeadLock’s data leak site has listed 80 organizations across various sectors, including IT, mining, transportation, manufacturing, hospitality, and consumer goods. The affected companies are predominantly based in Europe, with Microsoft researchers noting that multiple groups, including affiliates tied to the Lynx and INC ransomware ecosystems, have been deploying the malware.
The DeadLock operators’ use of blockchain is a departure from traditional tactics employed by ransomware gangs. By storing configuration data and leak site postings on the Polygon blockchain, they can dynamically generate chat-proxy addresses without relying on conventional domains or web servers. This approach allows them to replace proxy servers without modifying the victim-facing application, effectively reducing their dependence on easily identifiable infrastructure.
However, Microsoft’s report highlights that while this tactic provides some level of resilience against takedown efforts, it is not foolproof. Communications still require a custom proxy, public Polygon RPC endpoints must remain accessible, and files hosted on Wasabi cloud services can be removed, rendering the blockchain-based approach susceptible to disruptions.
Furthermore, an in-depth analysis by Microsoft reveals that DeadLock’s encryption scheme has been designed to bypass countries with strict data protection laws, including those in the former Soviet Union, Iran, Syria, Oman, and Yemen. The malware uses unique per-file XChaCha20 keys protected with Curve25519 elliptic curve cryptography, ensuring that each file is encrypted independently.
To mitigate the threat posed by DeadLock ransomware, organizations are advised to prioritize strengthening their endpoint defenses through cloud-delivered antivirus protection, EDR in block mode, tamper protection, automated investigation and remediation, and automatic attack disruption. Implementing Controlled Folder Access and enabling attack-surface reduction rules can also help prevent unauthorized file changes and lateral movement.
In a broader context, the DeadLock ransomware operation serves as a stark reminder of the evolving tactics employed by cybercriminals to evade detection and maximize their impact. As organizations continue to navigate the complex landscape of cybersecurity threats, it is essential that they remain vigilant and adapt their defenses accordingly to stay ahead of these emerging risks.
To defend against DeadLock ransomware attacks, it’s crucial for organizations to regularly review and update their security measures, focusing on endpoint defense, user education, and incident response planning. By doing so, businesses can minimize the risk of falling victim to this sophisticated threat and prevent significant financial losses due to data breaches and system downtime.
Source: Bleeping Computer — 2026-08-11