The DeadLock ransomware group is employing innovative decentralized technology to bolster its operations, making it more challenging for authorities to counteract. Utilizing blockchain-based methods, the group enhances its communication and data leakage strategies, according to Microsoft Threat Intelligence.
Decentralized Infrastructure and Double Extortion Tactics
DeadLock integrates the Session messaging network with blockchain services to support its extortion activities, providing a resilient operational framework. Microsoft reports that multiple threat actors, including affiliates of Lynx and INC ransomware, have used this malware since its detection in July 2025. Employing double extortion, DeadLock encrypts data and threatens public exposure of sensitive information, affecting victims primarily in Italy, Spain, Poland, Türkiye, and the United States.
Group-IB, a Singapore-based cybersecurity firm, highlights that despite its effective tactics, DeadLock maintains a lower profile compared to similar groups by avoiding known affiliate programs and lacking a dedicated data leak site. This strategic choice contributed to the late discovery of its initial victims in May 2026, according to Ransomware.Live.
Technical and Operational Innovations
DeadLock’s encryption strategy involves adding a “.dlock” extension, altering file icons, and changing desktop backgrounds to display ransom messages. It uses selective encryption, sparing specific directories and files, and combines Curve25519 elliptic-curve cryptography with the XChaCha20 cipher for secure file encryption.
Victims are instructed to utilize the decentralized Session app for communication and payment of ransoms in Bitcoin or Monero. In some cases, a “security report” is offered, detailing how the attack was conducted, with assurances against future targeting upon payment. Geolocation-based restrictions prevent execution in certain regions, while a resource-aware throttling mechanism optimizes system performance during encryption.
HTML-Based Recovery and Blockchain Integration
Distinctively, DeadLock employs an HTML file for recovery instructions, capable of facilitating encrypted chat and data access without a server. This file uses JavaScript to interact with Polygon smart contracts, enabling dynamic proxy server address rotation and enhancing resistance to censorship.
Microsoft notes that this blockchain-centric approach complicates traditional takedown efforts, providing DeadLock with a robust and adaptive communication infrastructure. This evolution in ransomware tactics underscores the increasing complexity of cyber threats and the need for advanced defensive strategies.
As cybersecurity experts continue to analyze and respond to these threats, the integration of decentralized technologies presents both challenges and opportunities for the ongoing battle against cybercrime.
