DeadLock is an emerging financially motivated ransomware operation first observed in July 2025. The group uses a double-extortion model, encrypting victim environments while also exfiltrating data and threatening publication through its leak platform known as the DeadLock blog. By mid-2026, the operation had claimed more than 80 victims, with reporting also placing the count in the mid-90s, and more than half of the publicly named victims were located in Europe. A distinguishing feature of DeadLock is its decentralized victim-facing infrastructure. The operation uses the Session messaging network for encrypted communications and blockchain-backed services, including Polygon-based smart-contract mechanisms, to distribute configuration data and support leak-blog functionality. Stolen files have also been made accessible through cloud-hosted storage. This architecture is intended to improve resilience against infrastructure disruption and takedown efforts compared with conventional ransomware leak sites and negotiation portals. DeadLock has targeted organizations across multiple sectors, including information technology, manufacturing, mining, transportation and logistics, hospitality, consumer goods, and healthcare-related organizations such as laboratories and biopharmaceutical firms. Victims have been reported across Europe, Asia, North America, South America, and Africa, with especially frequent victim reporting in Italy, Spain, Poland, Türkiye, and the United States. The malware itself is a Rust-based encryptor that uses a hybrid cryptographic design built around XChaCha20 and Curve25519. Reported behaviors include selective file encryption, privilege elevation, termination of services and processes, deletion of backups and shadow copies, event-log clearing or disabling, ransom-note deployment, wallpaper changes, and self-deletion. DeadLock also appears to implement geofencing or language-based exclusions to avoid execution in former Soviet and CIS-linked countries and certain Middle Eastern locales. Resource-aware throttling is used during encryption to keep systems responsive. Microsoft observed DeadLock being deployed by multiple threat actors rather than a single tightly bounded operator set. At least one observed deployer was linked to the Lynx and INC ransomware ecosystems, indicating affiliate-style or shared-operator use. DeadLock is therefore best understood as a ransomware operation or ecosystem with financially motivated extortion activity rather than a purely monolithic intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group that rose to third place in July 2026 with 10% of published attacks and 97 reported victims.
Emerging financially motivated ransomware group using decentralized infrastructure combining the Session messaging network and blockchain-backed services to support extortion operations, leak hosting, and negotiations. It uses double extortion, encrypting victim environments and threatening to publish exfiltrated data on the DeadLock blog.
Conducting double-extortion ransomware attacks using data theft, leak-site pressure, and file encryption, while leveraging decentralized infrastructure including Polygon blockchain-backed configuration retrieval and the Session network for victim communications.
Ransomware group using double extortion and decentralized, blockchain-backed infrastructure for victim communications, negotiation, and leak operations. It encrypts victim environments, threatens public release of exfiltrated data, uses Session for communications, HTML-based recovery chat, Polygon smart contracts for proxy rotation, geofencing to avoid CIS-linked and select Middle Eastern countries, and defense-evasion measures such as log erasure, registry changes, shadow copy deletion, and self-deletion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.