top of page

DeadLock changes how ransomware operates with blockchain

Microsoft Threat Intelligence published an analysis of DeadLock ransomware on August 10, 2026, showing that the group uses the Polygon blockchain to store infrastructure information while relying on Session for communications with victims. By July 2026, DeadLock had listed more than 80 organizations on its data leak site. The campaign is not associated with a specific CVE.

Blockchain has traditionally appeared in ransomware operations mainly as a payment mechanism through cryptocurrencies. DeadLock demonstrates a more significant shift: blockchain technology is now being incorporated directly into the infrastructure used to maintain communications, negotiations, and data leak operations.

For businesses, the key issue is not that blockchain makes the ransomware itself stronger at encrypting files. Instead, DeadLock uses blockchain to reduce its dependence on fixed domains and servers — infrastructure that defenders, hosting providers, or law enforcement have historically been able to block, seize, or take offline

deadlock-ransomware-blockchain
DeadLock changes how ransomware operates with blockchain

How has DeadLock changed the way ransomware operates?

Microsoft first observed DeadLock in July 2025. The operation now follows a double-extortion model, combining encryption of victim environments with threats to publish stolen data.

By July 2026, DeadLock had listed more than 80 organizations on its data leak site, with more than half located in Europe.

This number should be interpreted carefully. It represents organizations claimed by DeadLock as victims and does not mean every case has been independently verified by the affected organization or a third party.

A major change is how DeadLock handles communication after encrypting a victim's data. The malware leaves behind a file named RECOVERY_CHAT.<UID>.html. Rather than functioning as a simple ransom note containing contact details, the file acts as a self-contained web application with chat functionality, a leak-site interface, and a file browser.

Component

Role in DeadLock operations

DeadLock encryptor

Encrypts data on Windows systems

Polygon smart contracts

Store proxy addresses and blog content

Polygon RPC

Allows the application to retrieve blockchain data

Session

Provides a communications channel with victims

Proxy server

Connects the DeadLock interface to Session

Wasabi/S3-compatible storage

Stores images and some leaked data

Why does blockchain make DeadLock's infrastructure harder to disrupt?

Traditional ransomware operations often depend on domains, web servers, or hosting infrastructure controlled by threat actors. Once those systems are identified, authorities or service providers may be able to block or take them offline.

DeadLock reduces that dependency by storing certain critical information on Polygon. Microsoft identified two smart contracts used by the operation: one stores the proxy URL used for communications, while the other stores content for DeadLock's blog. The application on the victim's system queries public Polygon RPC endpoints to retrieve this information. (microsoft.com)

If one proxy is disrupted, operators can therefore update the address stored in the smart contract without redistributing a new ransom note or replacing the application already deployed on the victim's system.

DeadLock also uses Session, a decentralized messaging network, for communications with victims. The proxy address retrieved from blockchain acts as an intermediary between the victim's browser and the Session network. Leaked data may also be hosted on Wasabi through an Amazon S3-compatible interface.

What can DeadLock do after compromising a system?

Blockchain may be the most distinctive aspect of DeadLock's infrastructure, but the immediate business damage still occurs on endpoints and Windows environments.

Microsoft found that the ransomware uses a cryptographic design combining Curve25519 and XChaCha20. Each file receives a unique key, and Microsoft's current analysis found no practical decryption path without the attacker's private key. For large files, DeadLock can encrypt only selected portions to increase execution speed while still making the files unusable. (microsoft.com)

Before encryption, the malware can stop or disable multiple processes and services. Microsoft's analysis identified targets including Windows Defender, Volume Shadow Copy, Windows Backup, selected Hyper-V components, and services associated with Active Directory. (microsoft.com)

This matters because ransomware does not only threaten business files. If backup systems, virtualization platforms, or identity services are affected at the same time, containment and recovery may become significantly more difficult.

What should businesses do about this ransomware model?

Rather than focusing on whether blockchain should be blocked, organizations should prioritize preventing attackers from reaching the encryption and recovery-destruction stages.

Microsoft recommends enabling EDR in blocking mode, tamper protection, cloud-delivered protection, and automated attack disruption capabilities. CISA also recommends offline backups, recovery planning, MFA, system updates, and controls designed to limit ransomware propagation.

  • Enable EDR/XDR in prevention or blocking mode, not only alerting mode.

  • Enable tamper protection to prevent malware from disabling security tools.

  • Monitor attempts to stop Windows Defender, Volume Shadow Copy, and backup services.

  • Alert on Event Log deletion or abnormal log manipulation.

  • Separate backup administration privileges from normal administrative accounts.

  • Maintain offline or immutable backups and test recovery regularly.

  • Segment Active Directory, servers, hypervisors, endpoints, and backup infrastructure.

  • Control AnyDesk, RustDesk, and other remote administration tools through allowlists and policy.

  • Establish a baseline for blockchain and RPC traffic if legitimate business use exists.

  • Prepare procedures to isolate compromised accounts and endpoints as soon as ransomware indicators appear.

👉 Organizations that want to test whether an initial foothold could lead to privilege escalation or lateral movement can also use IPSIP Vietnam Pentest services to simulate attack paths in a controlled environment. Penetration testing does not replace EDR, firewalls, or continuous monitoring.

What does IPSIP Vietnam's expert perspective highlight?

Businesses should avoid building ransomware defenses primarily around static indicators of compromise. If threat actors can rotate infrastructure through smart contracts, behavioral detection, system segmentation, privileged-access controls, and reliable recovery capabilities become more sustainable defenses.

Organizations should first identify which systems would create the greatest operational impact if encrypted: Active Directory, ERP, file servers, hypervisors, production systems, or backup repositories. Those assets should be segmented, tightly permissioned, and monitored with sufficient telemetry to detect abnormal activity.

Ransomware recovery plans should also be tested rather than simply assuming backups are available. A useful test should answer three questions: Can a compromised administrator delete the backups? How long does full recovery actually take? And can the organization verify that a restored environment is clean before bringing it back into production?

ipsip-vietnam-cybersecurity-solutions
ISPIP Vietnam cybersecurity solutions
For businesses, the priority should not be finding a single tool that can “block blockchain.” The more sustainable approach is to prevent ransomware from reaching the encryption stage through privileged-access controls, continuous endpoint monitoring, segmentation of critical assets, protected backups, and tested incident response. As attacker infrastructure becomes more adaptable, an organization's ability to detect, contain, and recover needs to become the more stable layer of defense.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page