DeadLock is a Windows ransomware family first observed in July 2025 and associated with a financially motivated extortion operation. It is notable for combining conventional enterprise ransomware tradecraft with decentralized infrastructure for victim communications and operational resilience. The malware has been linked to multiple deploying groups, including affiliates associated with the Lynx and INC ransomware ecosystems, and reporting has described Russian-origin actor associations. Victims have been observed across multiple regions, with a concentration in Europe, and across sectors including IT, mining, transportation and logistics, manufacturing, hospitality, consumer goods, and healthcare-related organizations.
DeadLock supports double extortion by encrypting victim systems and pressuring organizations over stolen data. A distinctive feature is its use of Polygon smart contracts to store or rotate proxy and configuration data, an approach compared to EtherHiding-style blockchain-backed command-and-control. It also uses the Session decentralized messaging network for negotiations, and some variants drop a self-contained HTML recovery or chat application that facilitates encrypted victim-operator communication and can present leak-related content without relying on a traditional centralized backend. Reporting also describes use of cloud-hosted object storage for leaked data access.
On execution, DeadLock performs environment checks and appears to implement language- or geography-based exclusions, avoiding execution in various former Soviet, CIS-linked, and select Middle Eastern locales. It can attempt privilege elevation through UAC prompts and, when elevated, enables powerful privileges associated with debugging, backup, restore, ownership, auditing, and security control. Pre-encryption activity includes terminating processes, disabling services, clearing or disabling Windows event logs, deleting shadow copies and backup-related artifacts, and otherwise weakening recovery and defensive visibility. DeadLock has also been observed using Bring Your Own Vulnerable Driver techniques to disable endpoint protection at kernel level by exploiting CVE-2024-51324 in a Baidu security driver. Associated intrusion activity has included PowerShell-based defense impairment, AnyDesk for persistent remote access, and RDP for lateral movement.
The ransomware targets Windows environments and uses selective encryption logic intended to preserve system responsiveness and avoid rendering hosts unusable before extortion can proceed. Multiple reports describe custom cryptographic implementations rather than standard Windows APIs, including hybrid schemes based on Curve25519 and XChaCha20 with per-file key encapsulation, while other reporting characterizes the encryptor as a custom stream-cipher design with time-based keys. Encrypted files are renamed with the .dlock extension pattern, ransom notes are dropped in text and HTML formats, desktop wallpaper may be changed, and the malware can self-delete after completing encryption.
DeadLock is regarded as an emerging but technically notable ransomware family because it blends mature extortion behavior, anti-forensics, privilege escalation, BYOVD-based defense evasion, and blockchain-assisted infrastructure resilience.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The driver contains an improper privilege management flaw (CVE-2024-51324, CVSS 7.8) that lets any low-privilege user shut down protected processes, including EDR. | Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Deadlock's malware retrieves its connection instructions from a public blockchain, letting operators rotate addresses invisibly, with no domains or IP addresses for defenders to block or take down.
Attackers claim to have exfiltrated over 13,400 GB of data across the period... Attackers claimed to have stolen a total of 13,405.22 GB.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based ransomware encryptor that uses double extortion, encrypts victim files, appends the .dlock extension, drops ransom notes, clears logs, disables security and backup services, and uses decentralized recovery infrastructure built around the Session messaging network, Polygon blockchain, and Wasabi-hosted leak data.
Ransomware first observed in July 2025 that uses double extortion, encrypts victim files, threatens release of exfiltrated data, and employs decentralized infrastructure including Session and Polygon-backed services for victim communications, leak hosting, and negotiation resilience.
Ransomware group/family associated with double extortion: it encrypts files and exfiltrates data before pressuring victims. Affected files are reportedly renamed with the .dlock extension.
Ransomware that publicly names victims, uses blockchain-based C2 via a Polygon smart contract to rotate infrastructure, and employs BYOVD/kernel-level EDR termination before encryption. It uses Session for negotiations, AnyDesk for persistence, RDP for lateral movement, PowerShell for UAC bypass/defense evasion, and appends the .dlock extension to encrypted files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.