DeadLock is a financially motivated ransomware operation first observed in July 2025. It conducts double-extortion attacks, encrypting victim environments and threatening publication of exfiltrated data through its DeadLock blog. The operation has claimed victims across Europe, Asia, North America, South America, and Africa, with a substantial concentration in Europe. Confirmed targeting spans information technology, mining, transport and logistics, manufacturing, hospitality, consumer goods, and health-related organizations. DeadLock uses a decentralized victim-facing recovery and extortion architecture intended to complicate infrastructure disruption. Its ransom interface supports encrypted victim communications through the Session messaging network, while blockchain-backed services distribute configuration and leak-blog content. Stolen files are made available through cloud-based object storage. DeadLock also uses blockchain smart-contract reads to rotate proxy infrastructure without requiring redeployment of its victim-facing application. The ransomware uses hybrid Curve25519- and XChaCha20-based encryption, selective and size-dependent encryption routines, and resource throttling. It can attempt privilege elevation, terminate processes and services, delete backup artifacts, clear and disable Windows event logging, and self-delete after execution. It uses geographic and language-based execution exclusions that include former Soviet and CIS-linked environments and selected Middle Eastern countries. Microsoft has observed multiple threat actors deploying DeadLock, including an affiliate associated with the Lynx and INC Ransom ransomware ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe de ransomware figurant parmi les principaux acteurs recensés en juillet 2026.
A ransomware group attributed to a substantial share of July 2026 victim listings.
Conducting a ransomware attack resulting in a data breach against FBC in South Africa.
Conducting a ransomware attack resulting in a data breach against JP Molyneux Studio in the UK.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.