Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Iran calls out Trump’s ‘lies’ about US control over the Strait of Hormuz

    August 13, 2026

    Number of children in temporary accommodation hits record high

    August 13, 2026

    Style war: inside Wall Street’s battle to revive J Crew

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Iran calls out Trump’s ‘lies’ about US control over the Strait of Hormuz
    • Number of children in temporary accommodation hits record high
    • Style war: inside Wall Street’s battle to revive J Crew
    • Twitch faces backlash over Amazon using content to train AI
    • Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
    • B2C2 targets Asia’s family offices with Schroders veteran hire
    • A Green Oasis Grows in North Philadelphia’s Heat Island
    • Why Israel Won’t Make Qatar an Enemy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.

    “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat Intelligence team said.

    The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.

    DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. As of this month, the group has claimed 96 victims, with most of them located in Italy, Spain, Poland, Türkiye, and the U.S.

    In an analysis published earlier this January, Singapore-headquartered Group-IB said the group has managed to keep a lower profile than its peers owing to it not being associated with any known affiliate programs and for lacking a data leak site (DLS). According to Ransomware.Live, the first set of victims was not discovered until late May 2026.

    Attacks mounted by the group are known to encrypt files with the “.dlock” extension, change file icons using a custom “.ico” file written to disk, and modify the victim’s desktop wallpaper to display the message “Your infrastructure DeadLocked” and instruct them to open the ransom note.

    Cybersecurity

    The ransomware adopts a selective encryption model to exclude certain directories, file extensions, and file names from encryption. It employs a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption.

    The ransom note urges the victim to download a decentralized, end-to-end encrypted messaging application called Session to get in touch and make a Bitcoin or Monero payment after sharing a decrypted version of a locked file as proof. One version of the ransom note also claims to provide the compromised company with a “security report” that details the steps the attackers took to break into their network.

    Furthermore, the note states that victims who make a payment will receive security recommendations to stop future attacks, along with assurances that they will not be targeted again in the future.

    HTML recovery chat infrastructure summary

    Another important feature is its implementation of a language- or country-based geofencing to avoid execution in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries.

    Separately, it includes a “resource-aware throttling mechanism” that ensures system responsiveness as the encryption process is underway and pauses it when memory usage exceeds 29% or CPU load exceeds 70%, while relying on AnyDesk for remote control of compromised hosts. For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.

    The Windows version of the locker uses a PowerShell script to stop services that are not allowlisted and ensure they are not executed automatically after reboot. The script is also responsible for deleting Volume Shadow Copies and erasing itself in an attempt to cover its tracks. As a final cleanup step post successful encryption, the malware creates a batch script to delete its own binary from disk and then remove itself.

    Perhaps the most unusual aspect of the ransomware is its use of an HTML note (“RECOVERY_CHAT..html”) that’s dropped in all drive root directories and all Desktop folders.

    “Unlike the text note, the HTML note is a full interactive web application with a self-contained single-page application that implements end-to-end encrypted chat, a paginated data leak blog, and a file browser, all without requiring a traditional backend server,” Microsoft said.

    The purpose of the HTML file, as previously highlighted by Group-IB, is to facilitate direct communications between the DeadLock operator and the victim as an alternative to downloading the Session app. The HTML file sends and receives messages from a server that acts as a proxy, the details of which are retrieved and managed using a blockchain-based approach.

    Cybersecurity

    Specifically, this involves using JavaScript code within the HTML file that interacts with Polygon smart contracts for decentralized proxy server address rotation, turning them into a censorship- and takedown-resistant infrastructure that allows the operator to update the proxy URL without having to touch any victim-facing domains or register domains.

    “This exploit of smart contracts to deliver proxy addresses is an interesting method where attackers can literally apply infinite variants of this technique,” Group-IB said at the time.

    The recovery chat page also provides access to a data leak blog whose content is hosted on the Polygon blockchain, offering browsable access to the leaked files without running a web server via the Wasabi protocol. The two wallet addresses used by the threat actor are below –

    “This infrastructure model represents a meaningful evolution from traditional ransomware communication channels and poses new challenges for takedown efforts,” Microsoft said. “This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims.”

    contracts DeadLock Disrupt extortion harder Infra Polygon ransomware Smart
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    Venture Firm Team8 Secures Additional $365 Million

    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

    Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Iran calls out Trump’s ‘lies’ about US control over the Strait of Hormuz

    August 13, 2026

    Number of children in temporary accommodation hits record high

    August 13, 2026

    Style war: inside Wall Street’s battle to revive J Crew

    August 13, 2026

    Twitch faces backlash over Amazon using content to train AI

    August 13, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Iran calls out Trump’s ‘lies’ about US control over the Strait of Hormuz

    August 13, 2026

    Number of children in temporary accommodation hits record high

    August 13, 2026

    Style war: inside Wall Street’s battle to revive J Crew

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.