DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information.

First observed in July 2025, it had listed more than 80 alleged victims on its leak site by July 2026, with over half in Europe.

The reported victim count demonstrates both broad sector exposure and a steady public-pressure campaign intended to turn operational disruption into payment.

The operation has affected organisations in IT, mining, transport, manufacturing, hospitality, consumer goods, and other sectors across six continents.

Microsoft analysts identified DeadLock as a Rust-based encryptor whose operators pair double extortion with unusually durable communications.

Researchers did not name one initial-access method, but the malware can target a chosen directory, request administrator approval, and disrupt tools that could slow encryption.

The impact goes beyond inaccessible files. DeadLock deletes recovery material, targets backup, security, remote-access and cloud-sync processes, clears event logging, and leaves victims with a browser-based recovery page.

DeadLock icon for encrypted files (Source – Microsoft)

Researchers at Microsoft said in a report shared with Cyber Security News (CSN) that all these actions can delay containment when defenders need evidence and working backups most.

DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain

DeadLock’s standout feature is the way its recovery page uses Polygon blockchain smart contracts as a configuration store.

Instead of embedding one server address or relying on a domain that can be seized, the page makes read-only requests to retrieve the current proxy address and the group’s blog content.

Two contracts support this design: one provides the chat proxy location and another stores leak-blog posts. The page can rotate among six public Polygon RPC services, so one failed provider does not necessarily cut off access.

Service stop list (Source – Microsoft)

This echoes the wider trend covered in blockchain C2 infrastructure analysis, where attackers use a public ledger as a hard-to-remove lookup point.

That design changes, rather than eliminates, the takedown problem. Operators can update the proxy URL on-chain without redistributing the HTML page, while contract-hosted posts resist ordinary web-hosting removal.

Yet the system still depends on a reachable RPC service, the active proxy, and off-chain storage for images and stolen files.

The page routes victim messages through the Session network, which uses distributed, onion-routed messaging.

It also contains a file browser for material hosted through Wasabi-compatible storage. For defenders, blocking one website may not end communications, a lesson also illustrated by Ethereum hidden command servers.

Encryption and Defensive Priorities

DeadLock tries to keep a compromised system usable enough for the extortion process.

It pauses new encryption work when memory use rises above 29% or CPU load exceeds 70%, while using twice the number of CPU cores for directory-processing threads. That restraint can make activity less obvious, even as files become unusable.

Each file receives a separate encryption key, and larger files may be encrypted only in selected blocks to speed the attack.

List of skipped extensions and file names (Source – Microsoft)

Encrypted items gain a .dlock extension, while text notes and an HTML recovery chat direct victims toward the operators. The approach reinforces why ransomware response planning guidance must cover data protection and rapid isolation.

Organisations should maintain strong credential hygiene, harden systems, enable cloud-delivered protection or an equivalent, and use tamper protections so attackers cannot simply stop security services.

DeadLock wallpaper (Source – Microsoft)

Teams should also protect backups, review suspicious use of PSExec and WMI, and test controls before an incident.

Endpoint detection configured to block malicious activity can help contain an intrusion, while strict folder protections can limit unauthorised writes to valuable data. The value of quick containment is clear in ransomware attack isolation case.

DeadLock file footer (Source – Microsoft)

DeadLock shows that ransomware disruption now requires more than domain blocking.

Security teams need visibility on endpoints and outbound connections to public blockchain services, tested recovery procedures, and rehearsed incident-response decisions.

Early detection matters because the malware’s cleanup and logging changes can rapidly reduce evidence available to investigators.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4 DeadLock ransomware encryptor
URL deadlock.liveblog365[.]com Leak site domain
URL dlock.liveblog365[.]com Leak site domain
URL deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion Leak site domain
URL deadlockblog.great-site[.]net Leak site domain
URL deadlockblog.medianewsonline[.]com Leak site domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world