Multiple reports highlight evolving ransomware tactics and growing operational scale across distinct groups. Group-IB reported that DeadLock is using Polygon smart contracts to help obscure and rapidly rotate infrastructure used to connect victims to the gang, complicating defender blocking and analysis. After encryption, DeadLock reportedly drops an HTML file that wraps the Session messenger workflow; the smart contract stores a proxy URL that can be frequently changed, supporting an “encryption-only” model without a traditional public data leak site.
Separately, Darktrace summarized late-2025/early-2026 intelligence indicating Medusa (aka Storm-1175 / Spearwing) has become one of the most active RaaS operations, with reporting that 500+ organizations have been impacted and that affiliates leverage vulnerabilities for access, including Fortra GoAnywhere MFT CVE-2025-10035 and multiple SimpleHelp issues (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728). Trellix research (via DataBreaches/Industrial Cyber) described CrazyHunter as a Prince ransomware fork written in Go, with enhanced intrusion and evasion techniques and a focus on Taiwan healthcare, citing six confirmed victims and use of a data leak site to pressure targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On January 14, 2026, reporting on Group-IB research disclosed that DeadLock was using Polygon smart contracts to store rotatable proxy server URLs, making its command-and-control infrastructure harder to analyze and block.
By January 2026, Trellix reported that the CrazyHunter ransomware campaign had escalated, with six confirmed healthcare victims in Taiwan. The report said the group had evolved rapidly, using enhanced intrusion techniques, anti-malware evasion, and a data leak site consistent with double extortion.
Darktrace says Medusa's growth drew a joint advisory from CISA and the FBI, reflecting official concern over the group's expanding activity and tradecraft.
According to Darktrace, Medusa grew into one of the top 10 most active ransomware threat actors during 2025 through broad opportunistic targeting, RMM abuse, and exploitation of public-facing vulnerabilities.
Darktrace describes a Q4 2025 Medusa-linked incident in Europe involving long-lived SimpleHelp command-and-control, large-scale data exfiltration, and eventual ransomware execution.
The Register notes that Google Threat Intelligence Group reported the 'EtherHiding' technique in October 2025, documenting smart-contract abuse in North Korean activity. This provided prior precedent for blockchain-based attacker infrastructure similar to DeadLock's later methods.
Group-IB says the DeadLock ransomware operation was first observed in July 2025. The group targeted a range of organizations while keeping a relatively low profile.
Trellix assesses CrazyHunter as a fork of the Prince ransomware family, which was first seen in mid-2024. This places Prince as the earlier codebase from which CrazyHunter likely evolved.
Darktrace reports observing Medusa-related encryption activity in customer environments beginning in December 2023, indicating the ransomware operation was active well before its later surge in prominence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcedarktrace.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.