<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DeadLock - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/deadlock/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 18:45:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/deadlock/feed.xml" rel="self" type="application/rss+xml"/><item><title>DeadLock Ransomware Leverages Polygon Smart Contracts for Resilient C2</title><link>https://feed.craftedsignal.io/briefs/2026-08-deadlock-ransomware/</link><pubDate>Tue, 11 Aug 2026 18:45:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-deadlock-ransomware/</guid><description>The DeadLock ransomware group employs decentralized infrastructure, including Polygon smart contracts, to rotate proxy servers and host data leak blogs, complicating traditional takedown efforts.</description><content:encoded><![CDATA[<p>DeadLock ransomware, active since July 2025, has evolved its operational infrastructure to utilize decentralized technologies. The group uses a custom recovery ecosystem that integrates the Session messaging network with blockchain-backed services to manage communications and data exfiltration. By leveraging Polygon smart contracts, DeadLock operators can dynamically update proxy server addresses for their interactive HTML-based recovery chat and maintain a decentralized data leak blog via the Wasabi protocol. This architecture eliminates reliance on traditional, disruptible web infrastructure. The ransomware uses a hybrid cryptographic design (Curve25519 and XChaCha20) and features geofencing, resource-aware throttling (capping CPU/memory usage), and extensive defense evasion techniques. With 96 victims identified primarily in Italy, Spain, Poland, Türkiye, and the U.S., the group continues to expand its reach by partnering with affiliates of other ransomware operations like Lynx and INC.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is established, often involving the use of AnyDesk for remote control of compromised hosts.</li>
<li>The ransomware payload is deployed, which performs environment reconnaissance and applies geofencing to avoid specific CIS and Middle Eastern regions.</li>
<li>A PowerShell script is executed to identify and stop non-allowlisted services and prevent their automatic restart.</li>
<li>The malware clears event logs and modifies the Registry to disable further logging, effectively minimizing forensic footprint.</li>
<li>Volume Shadow Copies are deleted to prevent easy file recovery, followed by the encryption of files using the .dlock extension.</li>
<li>The ransomware performs resource-aware throttling to maintain system responsiveness, pausing encryption if CPU load exceeds 70% or memory exceeds 29%.</li>
<li>A custom &quot;.ico&quot; file is written to disk to modify file icons, and the desktop wallpaper is updated with a ransom notification.</li>
<li>The malware drops a self-contained HTML file (RECOVERY_CHAT.&lt;UID&gt;.html) to drive roots and Desktop folders, which facilitates communication and data leak access via Polygon-hosted proxy addresses.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>DeadLock ransomware has successfully targeted 96 organizations as of August 2026. Victims suffer from double extortion, where sensitive data is exfiltrated and threatened for release on a decentralized blog. The use of blockchain-based infrastructure increases the persistence of the threat actor's communications, making it significantly harder for law enforcement and security teams to disrupt the negotiation and extortion phases.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rules provided in this brief to detect the drop and execution of the ransom recovery HTML files.</li>
<li>Implement monitoring for PowerShell scripts that interact with shadow copy deletion commands, such as 'vssadmin delete shadows'.</li>
<li>Monitor for unauthorized use of remote access tools like AnyDesk within the environment.</li>
<li>Configure SIEM rules to alert on abnormal Registry modifications intended to disable Windows Event Logging.</li>
<li>Block egress traffic to the identified proxy server IP (138.226.236.51) at the firewall or DNS resolver level.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ransomware</category><category>blockchain</category><category>extortion</category><category>data-exfiltration</category></item></channel></rss>