Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DeadLock Ransomware Enhances Resilience with Blockchain

DeadLock Ransomware Enhances Resilience with Blockchain

Posted on August 11, 2026 By CWS

The DeadLock ransomware group is employing innovative decentralized technology to bolster its operations, making it more challenging for authorities to counteract. Utilizing blockchain-based methods, the group enhances its communication and data leakage strategies, according to Microsoft Threat Intelligence.

Decentralized Infrastructure and Double Extortion Tactics

DeadLock integrates the Session messaging network with blockchain services to support its extortion activities, providing a resilient operational framework. Microsoft reports that multiple threat actors, including affiliates of Lynx and INC ransomware, have used this malware since its detection in July 2025. Employing double extortion, DeadLock encrypts data and threatens public exposure of sensitive information, affecting victims primarily in Italy, Spain, Poland, Türkiye, and the United States.

Group-IB, a Singapore-based cybersecurity firm, highlights that despite its effective tactics, DeadLock maintains a lower profile compared to similar groups by avoiding known affiliate programs and lacking a dedicated data leak site. This strategic choice contributed to the late discovery of its initial victims in May 2026, according to Ransomware.Live.

Technical and Operational Innovations

DeadLock’s encryption strategy involves adding a “.dlock” extension, altering file icons, and changing desktop backgrounds to display ransom messages. It uses selective encryption, sparing specific directories and files, and combines Curve25519 elliptic-curve cryptography with the XChaCha20 cipher for secure file encryption.

Victims are instructed to utilize the decentralized Session app for communication and payment of ransoms in Bitcoin or Monero. In some cases, a “security report” is offered, detailing how the attack was conducted, with assurances against future targeting upon payment. Geolocation-based restrictions prevent execution in certain regions, while a resource-aware throttling mechanism optimizes system performance during encryption.

HTML-Based Recovery and Blockchain Integration

Distinctively, DeadLock employs an HTML file for recovery instructions, capable of facilitating encrypted chat and data access without a server. This file uses JavaScript to interact with Polygon smart contracts, enabling dynamic proxy server address rotation and enhancing resistance to censorship.

Microsoft notes that this blockchain-centric approach complicates traditional takedown efforts, providing DeadLock with a robust and adaptive communication infrastructure. This evolution in ransomware tactics underscores the increasing complexity of cyber threats and the need for advanced defensive strategies.

As cybersecurity experts continue to analyze and respond to these threats, the integration of decentralized technologies presents both challenges and opportunities for the ongoing battle against cybercrime.

The Hacker News Tags:Blockchain, Cryptography, cyber threats, Cybercrime, Cybersecurity, data extortion, DeadLock, Decentralized, Encryption, Group-IB, Microsoft, Polygon, Ransomware, Security, smart contracts

Post navigation

Previous Post: Delta Flight Wi-Fi Hacked Amid Cybersecurity Conference
Next Post: Microsoft Addresses 421 CVEs in August 2026 Patch Update

Related Posts

North Korean Cyber Group Targets Crypto Firm in Major Breach North Korean Cyber Group Targets Crypto Firm in Major Breach The Hacker News
Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks The Hacker News
Vercel Uncovers Additional Breach Linked to Context.ai Vercel Uncovers Additional Breach Linked to Context.ai The Hacker News
Malicious RubyGems Packages Threaten Developer Security Malicious RubyGems Packages Threaten Developer Security The Hacker News
First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package The Hacker News
Navigating the Mythos Era with Network Detection and Response Navigating the Mythos Era with Network Detection and Response The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zoom Security Flaws Enable Remote Code Execution
  • Microsoft Addresses 421 CVEs in August 2026 Patch Update
  • DeadLock Ransomware Enhances Resilience with Blockchain
  • Delta Flight Wi-Fi Hacked Amid Cybersecurity Conference
  • Adobe Issues Urgent Update for Critical Software Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zoom Security Flaws Enable Remote Code Execution
  • Microsoft Addresses 421 CVEs in August 2026 Patch Update
  • DeadLock Ransomware Enhances Resilience with Blockchain
  • Delta Flight Wi-Fi Hacked Amid Cybersecurity Conference
  • Adobe Issues Urgent Update for Critical Software Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark