Security1 distinct publisher3 min readUpdated
Microsoft says the crew fetches its chat-proxy address from a smart contract, so taking down domains no longer interrupts negotiation. Disruption moves back to the endpoint.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The DeadLock ransomware operation stores configuration data and its leak-site posts on the Polygon blockchain, and the victim-facing HTML page retrieves the current chat-proxy address by making a read-only eth_call against a smart contract rather than pointing at a fixed Tor URL [6][7]. That single design choice takes away the lever that law enforcement, registrars and hosting providers actually have, because a seizure no longer stops a victim from finding the negotiation channel [10].
The rest of the stack is built the same way. Victim communications ride the decentralized Session network, and stolen files are served from the Wasabi cloud service [9]. The operators can therefore replace the chat proxy without shipping a new build or a new note to victims, and their dependence on conventional domains and web servers falls accordingly [10]. Reading command-and-control addresses off a blockchain is not new among criminals generally, but Microsoft describes it as rare in ransomware specifically [8].
Microsoft is careful not to oversell the resilience, and the caveats are the interesting part. Communications still pass through the operators' custom proxy, public Polygon RPC endpoints have to stay reachable, and files parked on Wasabi can be removed, so the resistance to disruption is not absolute [11]. Those are three pressure points, but note what kind they are: two of them depend on third-party infrastructure providers choosing to act, and none of them recover an encrypted estate.
Scale first, so the design is not mistaken for a proof of concept. The actor emerged in mid-2025 running double extortion, and by July the leak site listed 80 organizations, mostly European [2][3]. Named victims span IT, mining, transportation, manufacturing, hospitality and consumer goods [4]. Microsoft observed the malware deployed by multiple groups, including an affiliate previously tied to the Lynx and INC ecosystems, which is the usual sign that a locker is being distributed rather than hand-operated [5].
The locker itself is conventional and competent. It skips former Soviet and CIS countries plus Iran, Syria, Oman and Yemen [12]. It deletes backups, stops virtualization and empties the Recycle Bin before encrypting non-system directories with per-file XChaCha20 keys wrapped using Curve25519 [13]. It is throttled to 29% of memory and 70% of CPU so the machine stays usable during encryption, and large files are intermittently encrypted in 512-byte blocks [14][15]. Files get a victim identifier and a .dlock extension, icons change, TXT notes drop, and the wallpaper is replaced [16]. Payment is requested in Bitcoin or Monero in exchange for a decryptor, a promise to delete the data, the initial access vector and security advice [17].
If takedown is degraded, the remaining controls are the ones that stop the encryption event. Microsoft's recommendations are cloud-delivered antivirus, EDR in block mode, tamper protection, automated investigation and remediation, and automatic attack disruption, plus Controlled Folder Access and attack-surface reduction rules that block untrusted executables and lateral movement through PsExec and WMI [18][19]. A vendor insert in the same report claims that headline prevention rates hide post-access behaviour and that prevention drops sharply once attackers hold valid credentials, measured across 338 million simulations [20]; treat the framing as marketing, but the sequencing point is the same one DeadLock's architecture makes.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The DeadLock ransomware operation uses a decentralized infrastructure relying on blockchain-backed services to protect its communication with victims and its data-leak activity.
The DeadLock threat actor emerged in mid-2025 and uses double-extortion tactics, combining data theft and leaking with file encryption.
By July, DeadLock's data leak site listed 80 organizations, mostly from Europe.
DeadLock victims include companies in the IT, mining, transportation, manufacturing, hospitality and consumer goods sectors.
Microsoft researchers observed the DeadLock malware being deployed by multiple groups, including an affiliate previously linked to the Lynx and INC ransomware ecosystems.
DeadLock operators use the Polygon blockchain to store configuration data and the posts on their leak site.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor research, relayed by one outlet
The technical detail is specific and internally consistent - on-chain configuration, eth_call proxy resolution, Session and Wasabi dependencies, XChaCha20/Curve25519 keying, resource caps, 512-byte intermittent encryption - and is attributed to Microsoft research including its own limiting caveats. But the cluster contains a single publisher summarizing a report that is neither linked nor quoted, and no indicators of compromise, contract addresses, or independent corroboration are supplied.
Active operation, technique still rare in ransomware
Adoption of the operation itself is concrete: 80 organizations listed on the leak site by July, mostly European, across six named sectors, with the locker deployed by more than one group including a Lynx/INC-linked affiliate. Adoption of the blockchain-resolved infrastructure pattern within ransomware is explicitly described as rare, so the technique is proven in production but not yet widespread.
Slightly overstated resilience
The framing that seizures no longer bite runs ahead of what the same reporting concedes: negotiation still depends on a custom proxy, public Polygon RPC endpoints must remain reachable, and Wasabi-hosted stolen files can be deleted, so several conventional takedown levers survive. The overstatement is modest because the source itself publishes those caveats and the underlying mechanics are described concretely rather than speculatively.
Vendor research plus in-article product promotion
The findings originate with Microsoft, whose recommended mitigations are its own endpoint product features - cloud-delivered antivirus, EDR in block mode, tamper protection, automated investigation and remediation, attack disruption, Controlled Folder Access and ASR rules - so the research doubles as product positioning. The article additionally carries a promotional block for the Blue Report 2026 with a 'Get the report' call to action, layering a second vendor's marketing onto the same narrative that prevention must be bought at the endpoint.
Plausible and specific, but single-sourced
Confidence is limited chiefly by structure rather than substance: one publisher, one upstream vendor, no linked primary report, no IOCs, and no comment from Polygon RPC operators, Session, Wasabi or law enforcement. Offsetting that, the mechanism is technically coherent, the actor's victim list is quantified, and the source publishes the researcher's own caveats instead of only the headline claim.
security
The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation1 distinct publisher
security
Two years, 117 identified children: the only Com case this week with an outcome attached1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
product
Nebius funds $4.5bn of AI capacity on terms that pay lenders mostly in stock2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 11, 2026