DeadLock Ransomware Leverages Blockchain for Resilient Operations
The DeadLock ransomware operation, active since mid-2025, has adopted a decentralized infrastructure to evade disruption, using blockchain-backed services to secure communications and data-leak activities. Employing double-extortion tactics encrypting files while threatening to leak stolen data the group has targeted 80 organizations by July 2025, primarily in Europe, across sectors including IT, mining, transportation, manufacturing, hospitality, and consumer goods.
Microsoft researchers identified multiple deployment groups behind DeadLock, including an affiliate previously linked to the Lynx and INC ransomware ecosystems. The operation stands out for its use of the Polygon blockchain to store configuration data and leak-site posts, replacing traditional Tor URLs with smart contract queries to retrieve command-and-control (C2) addresses. This tactic, while common among cybercriminals, remains rare in ransomware.
DeadLock further enhances resilience by using the decentralized Session network for encrypted victim communications and Wasabi cloud storage for hosting stolen files. These measures allow operators to swap proxies without modifying victim-facing apps, reducing reliance on takedown-prone domains. However, Microsoft notes that disruptions remain possible public Polygon RPC endpoints must stay accessible, and Wasabi-hosted files can still be removed.
The ransomware’s encryption scheme avoids systems in the former Soviet Union, CIS region, Iran, Syria, Oman, and Yemen. After disabling backups, virtualization, and clearing the Recycle Bin, it encrypts non-system directories using XChaCha20 keys protected by Curve25519 elliptic curve cryptography. To minimize detection, DeadLock caps resource usage at 29% memory and 70% CPU, allowing victims limited system access during encryption. Large files are partially encrypted in 512-byte blocks for speed, while encrypted data is marked with a victim-specific ID and the .dlock extension.
Ransom demands are made in Bitcoin or Monero, with attackers offering a decryptor, data-deletion assurances, breach details, and security recommendations in exchange for payment. Microsoft’s analysis underscores DeadLock’s evasive techniques while highlighting potential vulnerabilities in its decentralized infrastructure.
Exelasis cybersecurity rating report: https://www.rankiteo.com/company/exelasis-ltd
"id": "EXE1786487016",
"linkid": "exelasis-ltd",
"type": "Ransomware",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['IT',
'Mining',
'Transportation',
'Manufacturing',
'Hospitality',
'Consumer Goods'],
'location': 'Europe',
'type': 'Organization'}],
'attack_vector': 'Double-extortion (encryption + data leak threats)',
'data_breach': {'data_encryption': 'XChaCha20 keys protected by Curve25519 '
'elliptic curve cryptography',
'data_exfiltration': 'Yes (threatened as part of '
'double-extortion)',
'type_of_data_compromised': 'Stolen data (unspecified types)'},
'date_detected': '2025-07-01',
'description': 'The DeadLock ransomware operation, active since mid-2025, has '
'adopted a decentralized infrastructure to evade disruption, '
'using blockchain-backed services to secure communications and '
'data-leak activities. Employing double-extortion tactics, the '
'group encrypts files while threatening to leak stolen data. '
'The operation has targeted 80 organizations by July 2025, '
'primarily in Europe, across sectors including IT, mining, '
'transportation, manufacturing, hospitality, and consumer '
'goods. Microsoft researchers identified multiple deployment '
'groups behind DeadLock, including an affiliate previously '
'linked to the Lynx and INC ransomware ecosystems. The '
'operation uses the Polygon blockchain to store configuration '
'data and leak-site posts, replacing traditional Tor URLs with '
'smart contract queries to retrieve command-and-control (C2) '
'addresses. DeadLock also uses the decentralized Session '
'network for encrypted victim communications and Wasabi cloud '
'storage for hosting stolen files.',
'impact': {'data_compromised': 'Stolen data leaked as part of '
'double-extortion tactics',
'operational_impact': 'Limited system access during encryption '
'(resource usage capped at 29% memory and '
'70% CPU)',
'systems_affected': 'Non-system directories encrypted, backups '
'disabled, virtualization disrupted'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': 'Use of decentralized '
'infrastructure (Polygon '
'blockchain, Session network, '
'Wasabi cloud storage) to evade '
'disruption'},
'ransomware': {'data_encryption': 'Yes (XChaCha20 + Curve25519, .dlock '
'extension)',
'data_exfiltration': 'Yes',
'ransom_demanded': 'Bitcoin or Monero',
'ransomware_strain': 'DeadLock'},
'references': [{'source': 'Microsoft Research'}],
'response': {'third_party_assistance': 'Microsoft researchers'},
'threat_actor': 'DeadLock ransomware group (affiliates linked to Lynx and INC '
'ransomware ecosystems)',
'title': 'DeadLock Ransomware Leverages Blockchain for Resilient Operations',
'type': 'Ransomware'}