Blockchain-backed ransomware resists law enforcement takedown tactics
DeadLock ransomware uses blockchain to store its configuration and communications, making it harder to shut down than traditional ransomware operations. By July 2026, the group had targeted 80 organizations in Europe.
DeadLock, a ransomware operation that emerged in mid-2025, is using blockchain technology to protect its communications and resist disruption by law enforcement. According to BleepingComputer's coverage of Microsoft research, the group stores configuration data and leak-site content on the Polygon blockchain and uses the Session network to encrypt communications with victims. This approach allows the operators to change contact points without modifying their victim-facing application, reducing dependence on conventional domains that can be taken down.
By July 2026, DeadLock had listed 80 organizations on its leak site, primarily in Europe, across sectors including IT, mining, and manufacturing. The ransomware employs double-extortion tactics: stealing data and encrypting files to pressure victims for Bitcoin or Monero payments. While the decentralized infrastructure makes the operation more resilient, Microsoft notes that complete immunity is not possible, since the custom proxy must remain functional, blockchain endpoints must stay accessible, and files hosted on cloud services can still be removed.