DeadLock deploys blockchain to shield ransomware extortion network

DeadLock ransomware uses Polygon blockchain smart contracts to manage its extortion operations, making disruption harder than traditional ransomware infrastructure.

A ransomware group called DeadLock is using blockchain technology and decentralized services to make its extortion infrastructure harder to shut down, according to analysis by Microsoft Threat Intelligence reported by The Hacker News. The group uses the Session messaging app for victim contact and deploys smart contracts on the Polygon blockchain to manage proxy server addresses, allowing attackers to change communication routes without registering new domains. An interactive HTML file dropped on infected computers contains encrypted chat, a data leak portal, and file browser—all self-contained without needing a traditional server.

Since first appearing in July 2025, DeadLock has claimed 96 victims, mostly in Italy, Spain, Poland, Türkiye, and the U.S. The ransomware encrypts files with a ".dlock" extension, uses advanced cryptography, and includes safeguards to pause encryption if system resources spike. It also erases logs and deletes shadow copies to remove traces. Microsoft noted that this decentralized approach represents a significant shift in ransomware infrastructure and creates new obstacles for takedown efforts.