conv.

All stories
SecurityActive · 8h

DeadLock ransomware embeds itself on Polygon blockchain to evade takedowns

Microsoft reports the group stores extortion infrastructure on-chain, making traditional law enforcement disruption tactics far harder to execute.

DeadLock ransomware embeds itself on Polygon blockchain to evade takedowns
cyberworldops.eu

Conversation activity · last 9 hours peak 4/15m

Peak 4 items in one 15m at Aug 11, 6 PM; 8 items over 9 hours Aug 11, 12:08 PM — no itemsAug 11, 12:23 PM — 3 items · Google News 3Aug 11, 12:38 PM — no itemsAug 11, 12:53 PM — no itemsAug 11, 1:08 PM — no itemsAug 11, 1:23 PM — no itemsAug 11, 1:38 PM — no itemsAug 11, 1:53 PM — no itemsAug 11, 2:08 PM — 1 item · Mastodon 1Aug 11, 2:23 PM — no itemsAug 11, 2:38 PM — no itemsAug 11, 2:53 PM — no itemsAug 11, 3:08 PM — no itemsAug 11, 3:23 PM — no itemsAug 11, 3:38 PM — no itemsAug 11, 3:53 PM — no itemsAug 11, 4:08 PM — no itemsAug 11, 4:23 PM — no itemsAug 11, 4:38 PM — no itemsAug 11, 4:53 PM — no itemsAug 11, 5:08 PM — no itemsAug 11, 5:23 PM — no itemsAug 11, 5:38 PM — no itemsAug 11, 5:53 PM — no itemsAug 11, 6:08 PM — 4 items · Mastodon 4Aug 11, 6:23 PM — no itemsAug 11, 6:38 PM — no itemsAug 11, 6:53 PM — no itemsAug 11, 7:08 PM — no itemsAug 11, 7:23 PM — no itemsAug 11, 7:38 PM — no itemsAug 11, 7:53 PM — no itemsAug 11, 8:08 PM — no itemsAug 11, 8:23 PM — no itemsAug 11, 8:38 PM — no itemsAug 11, 8:53 PM — no items 4 items · 6:08 PM
2 PM4 PM6 PMnow · 9:08 PM

Summary, timeline and people extracted by Claude from 8 items across 2 sources · 47m ago. Quotes are verbatim.

DeadLock, a ransomware operation first detected in July 2025, is using Polygon smart contracts and the Session encrypted messaging network to host its victim communication and data-leak infrastructure, eliminating the need for traditional centralized servers or domains. The decentralized design allows operators to rotate contact points and posted stolen data without updating hardcoded URLs, significantly complicating law enforcement takedown efforts. As of August 2026, the group has claimed 96 victims across Europe and the U.S.

  • DeadLock stores ransomware infrastructure (victim chat portals, data-leak blogs) on Polygon smart contracts instead of traditional servers, eliminating single points of takedown.
  • Operators can rotate proxy URLs and update stolen file locations on-chain without changing hardcoded domains in the ransom note, making domain-blocking and DNS disruption ineffective.
  • The group has claimed 96 victims as of August 2026, primarily in Italy, Spain, Poland, Turkey, and the U.S., with deployments by multiple threat actors including Lynx and INC affiliates.
  • Infosec community views this as a significant innovation: blockchain technology repurposed as command-and-control infrastructure rather than for financial ransomware payments.

How it unfolded

  1. Reaction Infosec community reaction on Mastodon

    Security professionals on Mastodon note the significance of blockchain being repurposed for non-financial crime, specifically as a command-and-control infrastructure rather than for traditional financial ransomware payments.

    “blockchain being used for crimes that are not financial in nature, but as a c2!”

    Viss · Mastodon ↗
  2. Cybersecurity outlets and threat intelligence platforms amplify Microsoft's disclosure of DeadLock's blockchain-based infrastructure, emphasizing the novelty of using decentralized systems for ransomware command and control.

  3. Microsoft reveals that DeadLock stores C2 configuration and victim negotiation infrastructure on Polygon blockchain smart contracts, using Session for encrypted messaging and Wasabi S3 buckets for stolen file storage.

    “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.”

    Microsoft Threat Intelligence team · Google News ↗
  4. 15 weeks quiet
  5. The first set of victims claimed by DeadLock is discovered, marking the group's emergence in public threat intelligence.

  6. 17 weeks quiet
  7. Group-IB analysis describes DeadLock as keeping a lower profile than peers, noting it has no known affiliate programs and lacks a traditional data-leak site.

  8. 26 weeks quiet
  9. DeadLock emerges as a new ransomware operation employing double extortion tactics—encrypting victim environments and threatening to publicly release stolen data.

What people are saying verbatim

“Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.”

Microsoft Threat Intelligence team, Ransomware analyst · The Hacker News ↗

“Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one.”

cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗

“Knock the proxy offline, and the crew simply updates the on-chain value — every note already sitting on victim machines starts pointing at the replacement.”

cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗

“Microsoft calls the setup "a notable evolution in ransomware infrastructure design."”

cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗

“blockchain being used for crimes that are not financial in nature, but as a c2!”

Viss, Mastodon infosec user · Mastodon ↗

“The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder.”

cyberworldops, Threat intelligence account · Mastodon ↗

The conversation positions from the crowd, verbatim

Security professionals are focused on the technical innovation of using blockchain for ransomware C2 rather than traditional financial payments, treating this as a notable evolution in ransomware infrastructure design that complicates law enforcement and private-sector takedown operations.

most voices

This represents a significant innovation in ransomware resilience that will complicate takedown efforts.

  • “Microsoft calls the setup "a notable evolution in ransomware infrastructure design."”

    cyberkendra.com · cyberkendra.com ↗
  • “The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder.”

    cyberworldops · Mastodon ↗
some voices

Blockchain is being misused for criminal C2 infrastructure in novel ways beyond financial crime.

  • “blockchain being used for crimes that are not financial in nature, but as a c2!”

    Viss · Mastodon ↗

Voices from the web unedited

  • Microsoft Threat Intelligence reports DeadLock ransomware leveraging Polygon smart contracts for victim communications and stolen data publication. The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder. 96 victims claimed this month alone. # DeadLock # Ransomware # Polygon #…

    cyberworldops@infosec.exchangeMastodon · mas.to6h agoview on Mastodon ↗
  • The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/

    BleepingComputer@infosec.exchangeMastodon · journa.host2h agoview on Mastodon ↗
  • https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/ there we go blockchain being used for crimes that are not financial in nature, but as a c2!

    Viss@mastodon.socialMastodon · toot.community2h agoview on Mastodon ↗
  • Bleeping Computer: DeadLock ransomware uses blockchain to resist infrastructure takedown https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/

    headlines_bot@m.ai6yr.orgMastodon · newsie.social2h agoview on Mastodon ↗