{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/deadlock/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["DeadLock"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["ransomware","blockchain","extortion","data-exfiltration"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eDeadLock ransomware, active since July 2025, has evolved its operational infrastructure to utilize decentralized technologies. The group uses a custom recovery ecosystem that integrates the Session messaging network with blockchain-backed services to manage communications and data exfiltration. By leveraging Polygon smart contracts, DeadLock operators can dynamically update proxy server addresses for their interactive HTML-based recovery chat and maintain a decentralized data leak blog via the Wasabi protocol. This architecture eliminates reliance on traditional, disruptible web infrastructure. The ransomware uses a hybrid cryptographic design (Curve25519 and XChaCha20) and features geofencing, resource-aware throttling (capping CPU/memory usage), and extensive defense evasion techniques. With 96 victims identified primarily in Italy, Spain, Poland, Türkiye, and the U.S., the group continues to expand its reach by partnering with affiliates of other ransomware operations like Lynx and INC.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established, often involving the use of AnyDesk for remote control of compromised hosts.\u003c/li\u003e\n\u003cli\u003eThe ransomware payload is deployed, which performs environment reconnaissance and applies geofencing to avoid specific CIS and Middle Eastern regions.\u003c/li\u003e\n\u003cli\u003eA PowerShell script is executed to identify and stop non-allowlisted services and prevent their automatic restart.\u003c/li\u003e\n\u003cli\u003eThe malware clears event logs and modifies the Registry to disable further logging, effectively minimizing forensic footprint.\u003c/li\u003e\n\u003cli\u003eVolume Shadow Copies are deleted to prevent easy file recovery, followed by the encryption of files using the .dlock extension.\u003c/li\u003e\n\u003cli\u003eThe ransomware performs resource-aware throttling to maintain system responsiveness, pausing encryption if CPU load exceeds 70% or memory exceeds 29%.\u003c/li\u003e\n\u003cli\u003eA custom \u0026quot;.ico\u0026quot; file is written to disk to modify file icons, and the desktop wallpaper is updated with a ransom notification.\u003c/li\u003e\n\u003cli\u003eThe malware drops a self-contained HTML file (RECOVERY_CHAT.\u0026lt;UID\u0026gt;.html) to drive roots and Desktop folders, which facilitates communication and data leak access via Polygon-hosted proxy addresses.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eDeadLock ransomware has successfully targeted 96 organizations as of August 2026. Victims suffer from double extortion, where sensitive data is exfiltrated and threatened for release on a decentralized blog. The use of blockchain-based infrastructure increases the persistence of the threat actor's communications, making it significantly harder for law enforcement and security teams to disrupt the negotiation and extortion phases.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to detect the drop and execution of the ransom recovery HTML files.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for PowerShell scripts that interact with shadow copy deletion commands, such as 'vssadmin delete shadows'.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized use of remote access tools like AnyDesk within the environment.\u003c/li\u003e\n\u003cli\u003eConfigure SIEM rules to alert on abnormal Registry modifications intended to disable Windows Event Logging.\u003c/li\u003e\n\u003cli\u003eBlock egress traffic to the identified proxy server IP (138.226.236.51) at the firewall or DNS resolver level.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T18:45:27Z","date_published":"2026-08-11T18:45:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-deadlock-ransomware/","summary":"The DeadLock ransomware group employs decentralized infrastructure, including Polygon smart contracts, to rotate proxy servers and host data leak blogs, complicating traditional takedown efforts.","title":"DeadLock Ransomware Leverages Polygon Smart Contracts for Resilient C2","url":"https://feed.craftedsignal.io/briefs/2026-08-deadlock-ransomware/"}],"language":"en","title":"CraftedSignal Threat Feed - DeadLock","version":"https://jsonfeed.org/version/1.1"}