VMTech
Discuss a project

DeadLock builds ransomware communications around Polygon smart contracts

DeadLock builds ransomware communications around Polygon smart contracts

Microsoft Threat Intelligence has observed the DeadLock ransomware group using Polygon smart contracts to support victim communications and data-leak operations. First detected in July 2025, DeadLock had claimed 96 victims as of August 2026, with most reported in Italy, Spain, Poland, Türkiye and the United States.

The group uses double extortion: it encrypts victim environments and threatens to publish exfiltrated data. Microsoft said DeadLock’s recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used during the extortion process. Multiple threat actors have deployed the ransomware, including an affiliate associated with Lynx and INC ransomware.

An HTML recovery portal without a conventional backend

DeadLock drops an HTML file named RECOVERY_CHAT.<UID>.html in drive-root and Desktop folders. Microsoft described it as a self-contained single-page application that provides end-to-end encrypted chat, a paginated data-leak blog and a file browser. The page gives victims an alternative to downloading Session for negotiations.

JavaScript embedded in that file interacts with Polygon smart contracts to retrieve and manage rotating proxy-server addresses. This lets operators update a proxy URL without changing victim-facing domains or domain registrations. The leak blog is also hosted through Polygon, with browsable access to leaked files via the Wasabi protocol rather than a traditional web server.

Microsoft said this model can make portions of DeadLock’s communication, leak-hosting and negotiation infrastructure more resilient to disruption. That challenge sits alongside the wider criminal use of decentralized services examined in decentralized services complicate takedown paths, where infrastructure choices can complicate conventional investigative and takedown paths.

Locker behaviour and evasion measures

DeadLock encrypts files with the .dlock extension, changes file icons with a custom .ico file and sets a wallpaper reading “Your infrastructure DeadLocked.” Its ransom note asks victims to contact the operators through Session and pay in Bitcoin or Monero after receiving a decrypted file as proof.

The malware uses selective encryption and a hybrid design combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher. It avoids execution in former Soviet and CIS-linked environments and in selected Middle Eastern countries. A resource-aware throttling mechanism pauses encryption when memory use exceeds 29% or CPU load exceeds 70%.

For evasion, the Windows locker erases logs, modifies the Registry to disable future logging, and uses PowerShell to stop non-allowlisted services. The script deletes Volume Shadow Copies and erases itself, while a later batch script removes the ransomware binary after encryption. Organizations should preserve HTML ransom notes and related indicators during incident response, because the embedded recovery workflow may remain relevant even when a conventional domain or server is disrupted.

#ransomware#blockchainsecurity#threatintelligence#incidentresponse
Open analytics
On the site 0 views
min read 3 12.08.2026
Instagram

DeadLock builds ransomware communications around Polygon smart contracts

Open the post on Instagram ↗