DeadLock is a financially motivated, Rust-based Windows ransomware operation first observed in July 2025. It employs double extortion, encrypting victim data while threatening to publish exfiltrated information. The operation has affected organizations across Europe, Asia, North America, South America, and Africa, including IT, mining, transportation and logistics, manufacturing, hospitality, and consumer-goods sectors. DeadLock has been deployed by multiple threat actors, including an affiliate associated with the Lynx and INC ransomware ecosystems.
The encryptor uses language- and locale-based geofencing to avoid execution in former Soviet and CIS-linked countries and selected Middle Eastern environments. It can request administrator elevation, enable elevated privileges, terminate security, backup, virtualization, cloud synchronization, remote-access, and other processes and services, clear and disable Windows event logging, remove recovery material and Volume Shadow Copies, and delete itself after encryption. Reported activity also includes abuse of a vulnerable signed antivirus driver to disable endpoint security. DeadLock uses per-file symmetric encryption based on XChaCha20, with key material protected through Curve25519-based cryptography; its encryption design has been assessed as not practically recoverable without the operator-controlled private key. It selectively or partially encrypts larger files to improve speed and appends a victim-specific identifier and the .dlock extension to encrypted files.
DeadLock’s victim recovery workflow is notable for its decentralized architecture. Its self-contained HTML recovery application retrieves chat-proxy configuration and leak-blog content from Polygon smart contracts through public RPC services, uses the Session network for encrypted victim communications, and provides access to stolen files through Wasabi-compatible object storage. This design enables operators to rotate communications infrastructure without redistributing the recovery application and complicates conventional infrastructure takedowns, although it remains dependent on proxies, public blockchain access, messaging-network availability, and hosted storage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The driver contains an improper privilege management flaw (CVE-2024-51324, CVSS 7.8) that lets any low-privilege user shut down protected processes, including EDR. | Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
The malware sleeps for about 50 seconds before encrypting, defeating short sandbox detonation windows.
Another important feature is its implementation of a language- or country-based geofencing to avoid execution in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries.
DeadLock’s standout feature is the way its recovery page uses Polygon blockchain smart contracts as a configuration store. Instead of embedding one server address or relying on a domain that can be seized, the page makes read-only requests to retrieve the current proxy address and the group’s blog content.
Two contracts support this design: one provides the chat proxy location and another stores leak-blog posts.
The page routes victim messages through the Session network, which uses distributed, onion-routed messaging.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
it includes a "resource-aware throttling mechanism" that ensures system responsiveness as the encryption process is underway and pauses it when memory usage exceeds 29% or CPU load exceeds 70%, while relying on AnyDesk for remote control of compromised hosts.
Attackers claim to have exfiltrated over 13,400 GB of data across the period... Attackers claimed to have stolen a total of 13,405.22 GB.
Бизнес-логика ransomware-атаки укладывается в два действия: шифрование данных - Data Encrypted for Impact (T1486, Impact) - плюс угроза слить украденное, то есть двойное вымогательство.
The Windows version of the locker uses a PowerShell script to stop services that are not allowlisted and ensure they are not executed automatically after reboot.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly discussed ransomware/extortion operation with a modular victim-facing recovery and extortion workflow. Its portal uses Polygon smart contracts for configuration and leak-blog retrieval, Session for encrypted victim communications, and Wasabi-compatible object storage for leaked files, making individual infrastructure layers more replaceable and resistant to a single takedown.
Ransomware operation included in NCC Group's July activity rankings.
A newer ransomware family written in Rust, noted for decentralized negotiation infrastructure that complicates traditional server-seizure and interception methods.
Ransomware that uses a Polygon smart contract as a dead drop resolver to retrieve a rotating Session-messenger relay URL for C2-related communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.