Security1 publisher3 min readPublished Updated
DeadLock reads its ransom chat address off Polygon, and seizures stop biting
Microsoft says the crew fetches its chat-proxy address from a smart contract, so taking down domains no longer interrupts negotiation. Disruption moves back to the endpoint.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The DeadLock ransomware operation uses a decentralized infrastructure relying on blockchain-backed services to protect its communication with victims and its data-leak activity.
- The DeadLock threat actor emerged in mid-2025 and uses double-extortion tactics, combining data theft and leaking with file encryption.
- By July, DeadLock's data leak site listed 80 organizations, mostly from Europe.
- DeadLock victims include companies in the IT, mining, transportation, manufacturing, hospitality and consumer goods sectors.
- Microsoft researchers observed the DeadLock malware being deployed by multiple groups, including an affiliate previously linked to the Lynx and INC ransomware ecosystems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The DeadLock ransomware operation stores configuration data and its leak-site posts on the Polygon blockchain, and the victim-facing HTML page retrieves the current chat-proxy address by making a read-only eth_call against a smart contract rather than pointing at a fixed Tor URL [6][7]. That single design choice takes away the lever that law enforcement, registrars and hosting providers actually have, because a seizure no longer stops a victim from finding the negotiation channel [10].
The rest of the stack is built the same way. Victim communications ride the decentralized Session network, and stolen files are served from the Wasabi cloud service [9]. The operators can therefore replace the chat proxy without shipping a new build or a new note to victims, and their dependence on conventional domains and web servers falls accordingly [10]. Reading command-and-control addresses off a blockchain is not new among criminals generally, but Microsoft describes it as rare in ransomware specifically [8].
Microsoft is careful not to oversell the resilience, and the caveats are the interesting part. Communications still pass through the operators' custom proxy, public Polygon RPC endpoints have to stay reachable, and files parked on Wasabi can be removed, so the resistance to disruption is not absolute [11]. Those are three pressure points, but note what kind they are: two of them depend on third-party infrastructure providers choosing to act, and none of them recover an encrypted estate.
Scale first, so the design is not mistaken for a proof of concept. The actor emerged in mid-2025 running double extortion, and by July the leak site listed 80 organizations, mostly European [2][3]. Named victims span IT, mining, transportation, manufacturing, hospitality and consumer goods [4]. Microsoft observed the malware deployed by multiple groups, including an affiliate previously tied to the Lynx and INC ecosystems, which is the usual sign that a locker is being distributed rather than hand-operated [5].
The locker itself is conventional and competent. It skips former Soviet and CIS countries plus Iran, Syria, Oman and Yemen [12]. It deletes backups, stops virtualization and empties the Recycle Bin before encrypting non-system directories with per-file XChaCha20 keys wrapped using Curve25519 [13]. It is throttled to 29% of memory and 70% of CPU so the machine stays usable during encryption, and large files are intermittently encrypted in 512-byte blocks [14][15]. Files get a victim identifier and a .dlock extension, icons change, TXT notes drop, and the wallpaper is replaced [16]. Payment is requested in Bitcoin or Monero in exchange for a decryptor, a promise to delete the data, the initial access vector and security advice [17].
If takedown is degraded, the remaining controls are the ones that stop the encryption event. Microsoft's recommendations are cloud-delivered antivirus, EDR in block mode, tamper protection, automated investigation and remediation, and automatic attack disruption, plus Controlled Folder Access and attack-surface reduction rules that block untrusted executables and lateral movement through PsExec and WMI [18][19]. A vendor insert in the same report claims that headline prevention rates hide post-access behaviour and that prevention drops sharply once attackers hold valid credentials, measured across 338 million simulations [20]; treat the framing as marketing, but the sequencing point is the same one DeadLock's architecture makes.