DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
Brief
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information.
First observed in July 2025, it had listed more than 80 alleged victims on its leak site by July 2026, with over half in Europe.
The reported victim count demonstrates both broad sector exposure and a steady public-pressure campaign intended to turn operational disruption into payment.
The operation has affected organisations in IT, mining, transport, manufacturing, hospitality, consumer goods, and other sectors across six continents.
Microsoft analysts identified DeadLock as a Rust-based encryptor whose operators pair double extortion with unusually durable communications.
Researchers did not name one initial-access method, but the malware can target a chosen directory, request administrator approval, and disrupt tools that could slow encryption.
