DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.

“Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat Intelligence team said.

The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.

DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. As of this month, the group has claimed 96 victims, with most of them located in Italy, Spain, Poland, Türkiye, and the U.S.

In an analysis published earlier this January, Singapore-headquartered Group-IB said the group has managed to keep a lower profile than its peers owing to it not being associated with any known affiliate programs and for lacking a data leak site (DLS). According to Ransomware.Live, the first set of victims was not discovered until late May 2026.

Attacks mounted by the group are known to encrypt files with the “.dlock” extension, change file icons using a custom “.ico” file written to disk, and modify the victim’s wallpaper to display the message “Your infrastructure DeadLocked” and instruct them to open the ransom note.

The ransomware adopts a selective encryption model to exclude certain directories, file extensions, and file names from encryption. It employs a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption.

The ransom note urges the victim to download a decentralized, end-to-end encrypted messaging application called Session to get in touch and make a Bitcoin or Monero payment after sharing a decrypted version of a locked file as proof. One version of the ransom note also claims to provide the compromised company with a “security report” that details the steps the attackers took to break into their network.

Furthermore, the note states that victims who make a payment will receive security recommendations to stop future attacks, along with assurances that they will not be targeted again in the future.

Another important feature is its implementation of a language- or country-based geofencing to avoid execution in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries.

Separately, it includes a “resource-aware throttling mechanism” that ensures system responsiveness as the encryption process is underway and pauses it when memory usage exceeds 29% or CPU load exceeds 70%, while relying on AnyDesk for remote control of compromised hosts. For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events. 

The Windows version of the locker uses a PowerShell script to stop services that are not allowlisted and ensure they are not executed automatically after reboot. The script is also responsible for deleting Volume Shadow Copies and erasing itself in an attempt to cover its tracks. As a final cleanup step post successful encryption, the malware creates a batch script to delete its own binary from disk and then remove itself.

Perhaps the most unusual aspect of the ransomware is its use of an HTML note (“RECOVERY_CHAT.<UID>.html”) that’s dropped in all drive root directories and all Desktop folders.

“Unlike the text note, the HTML note is a full interactive web application with a self-contained single-page application that implements end-to-end encrypted chat, a paginated data leak blog, and a file browser, all without requiring a traditional backend server,” Microsoft said.

The purpose of the HTML file, as previously highlighted by Group-IB, is to facilitate direct communications between the DeadLock operator and the victim as an alternative to downloading the Session app. The HTML file sends and receives messages from a server that acts as a proxy, the details of which are retrieved and managed using a blockchain-based approach.

Specifically, this involves using JavaScript code within the HTML file that interacts with Polygon smart contracts for decentralized proxy server address rotation, turning them into a censorship- and takedown-resistant infrastructure that allows the operator to update the proxy URL without having to touch any victim-facing domains or domain registration.

“This exploit of smart contracts to deliver proxy addresses is an interesting method where attackers can literally apply infinite variants of this technique,” Group-IB said at the time.

The recovery chat page also provides access to a data leak blog whose content is hosted on the Polygon blockchain, offering browsable access to the leaked files without running a web server via the Wasabi protocol. The two wallet addresses used by the threat actor are below –

“This infrastructure model represents a meaningful evolution from traditional ransomware communication channels and poses new challenges for takedown efforts,” Microsoft said. “This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims.”

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.