DeadLock ransomware embeds itself on Polygon blockchain to evade takedowns
Microsoft reports the group stores extortion infrastructure on-chain, making traditional law enforcement disruption tactics far harder to execute.
Conversation activity · last 9 hours peak 4/15m
Summary, timeline and people extracted by Claude from 8 items across 2 sources · 47m ago. Quotes are verbatim.
DeadLock, a ransomware operation first detected in July 2025, is using Polygon smart contracts and the Session encrypted messaging network to host its victim communication and data-leak infrastructure, eliminating the need for traditional centralized servers or domains. The decentralized design allows operators to rotate contact points and posted stolen data without updating hardcoded URLs, significantly complicating law enforcement takedown efforts. As of August 2026, the group has claimed 96 victims across Europe and the U.S.
- DeadLock stores ransomware infrastructure (victim chat portals, data-leak blogs) on Polygon smart contracts instead of traditional servers, eliminating single points of takedown.
- Operators can rotate proxy URLs and update stolen file locations on-chain without changing hardcoded domains in the ransom note, making domain-blocking and DNS disruption ineffective.
- The group has claimed 96 victims as of August 2026, primarily in Italy, Spain, Poland, Turkey, and the U.S., with deployments by multiple threat actors including Lynx and INC affiliates.
- Infosec community views this as a significant innovation: blockchain technology repurposed as command-and-control infrastructure rather than for financial ransomware payments.
How it unfolded
-
Security professionals on Mastodon note the significance of blockchain being repurposed for non-financial crime, specifically as a command-and-control infrastructure rather than for traditional financial ransomware payments.
“blockchain being used for crimes that are not financial in nature, but as a c2!”
Viss · Mastodon ↗ -
Cybersecurity outlets and threat intelligence platforms amplify Microsoft's disclosure of DeadLock's blockchain-based infrastructure, emphasizing the novelty of using decentralized systems for ransomware command and control.
-
Microsoft reveals that DeadLock stores C2 configuration and victim negotiation infrastructure on Polygon blockchain smart contracts, using Session for encrypted messaging and Wasabi S3 buckets for stolen file storage.
“Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.”
Microsoft Threat Intelligence team · Google News ↗ - 15 weeks quiet
-
The first set of victims claimed by DeadLock is discovered, marking the group's emergence in public threat intelligence.
- 17 weeks quiet
-
Group-IB analysis describes DeadLock as keeping a lower profile than peers, noting it has no known affiliate programs and lacks a traditional data-leak site.
- 26 weeks quiet
-
DeadLock emerges as a new ransomware operation employing double extortion tactics—encrypting victim environments and threatening to publicly release stolen data.
What people are saying verbatim
“Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.”
Microsoft Threat Intelligence team, Ransomware analyst · The Hacker News ↗
“Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one.”
cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗
“Knock the proxy offline, and the crew simply updates the on-chain value — every note already sitting on victim machines starts pointing at the replacement.”
cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗
“Microsoft calls the setup "a notable evolution in ransomware infrastructure design."”
cyberkendra.com, Cybersecurity news outlet · cyberkendra.com ↗
“blockchain being used for crimes that are not financial in nature, but as a c2!”
Viss, Mastodon infosec user · Mastodon ↗
“The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder.”
cyberworldops, Threat intelligence account · Mastodon ↗
The conversation positions from the crowd, verbatim
Security professionals are focused on the technical innovation of using blockchain for ransomware C2 rather than traditional financial payments, treating this as a notable evolution in ransomware infrastructure design that complicates law enforcement and private-sector takedown operations.
This represents a significant innovation in ransomware resilience that will complicate takedown efforts.
-
“Microsoft calls the setup "a notable evolution in ransomware infrastructure design."”
cyberkendra.com · cyberkendra.com ↗ -
“The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder.”
cyberworldops · Mastodon ↗
Blockchain is being misused for criminal C2 infrastructure in novel ways beyond financial crime.
-
“blockchain being used for crimes that are not financial in nature, but as a c2!”
Viss · Mastodon ↗
Voices from the web unedited
-
Microsoft Threat Intelligence reports DeadLock ransomware leveraging Polygon smart contracts for victim communications and stolen data publication. The decentralized infrastructure, combined with Session encrypted messaging, makes takedown operations significantly harder. 96 victims claimed this month alone. # DeadLock # Ransomware # Polygon #…
-
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/
-
https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/ there we go blockchain being used for crimes that are not financial in nature, but as a c2!
-
Bleeping Computer: DeadLock ransomware uses blockchain to resist infrastructure takedown https://www. bleepingcomputer.com/news/secu rity/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/