Microsoft reported that the DeadLock ransomware operation has emerged as a financially motivated threat using double extortion and a decentralized recovery ecosystem designed to resist disruption. First observed in July 2025, DeadLock had listed more than 80 claimed victims by July 2026, with over half in Europe, and has affected organizations across multiple sectors and regions. Microsoft said the malware has been deployed by multiple groups, including an affiliate tied to the Lynx and INC ransomware ecosystems.
The Rust-based encryptor combines common ransomware tradecraft with an unusual communications and leak infrastructure. Microsoft said DeadLock attempts privilege escalation, terminates services and processes, clears event logs, selectively encrypts files, drops ransom notes, and self-deletes, while its recovery workflow relies on a local HTML chat app, the Session messaging network, Polygon smart contracts for configuration and blog data, and Wasabi-hosted stolen files exposed through an S3-compatible browser. The company also described DeadLock's hybrid cryptography using Curve25519 and XChaCha20 with per-file ephemeral keys, assessing the scheme as cryptographically sound and leaving no practical decryption path without the attackers' private key.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a detailed analysis of DeadLock ransomware, describing its Rust-based encryptor, decentralized recovery infrastructure, affiliate use across the Lynx and INC ecosystems, and cryptographic design. The report also provided indicators of compromise, detections, and mitigation guidance.
Microsoft reported that DeadLock had claimed 96 victims as of the reporting month, with most located in Italy, Spain, Poland, Türkiye, and the United States. This represents an increase from the more than 80 victims previously noted in July 2026.
As of July 2026, DeadLock operators had published more than 80 compromised organizations on the DeadLock blog. More than half of the claimed victims were in Europe, with victims spanning multiple sectors and regions.
Microsoft said it first observed the DeadLock ransomware operation in July 2025. The operation was tracked as an emerging financially motivated ransomware threat using double extortion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.