DeadLock is a financially motivated ransomware operation first observed in July 2025. It conducts double extortion by encrypting victim systems and threatening to publish exfiltrated data through the DeadLock blog. Its victims span Europe, Asia, North America, South America, and Africa, with a substantial concentration in Europe. Targeted sectors include information technology, mining, manufacturing, transportation and logistics, hospitality, consumer goods, healthcare, and telecommunications. Multiple threat actors have deployed DeadLock, including an affiliate previously associated with the Lynx and INC ransomware ecosystems; these associations do not establish that those operations are aliases of DeadLock. DeadLock uses decentralized victim-facing infrastructure to support negotiations and data disclosure. An interactive HTML ransom application retrieves a replaceable messaging-proxy address from a Polygon smart contract through read-only blockchain queries, with fallback RPC gateways providing redundancy. Victim communications pass through the Session messaging network. A separate Polygon contract supplies leak-blog content and attachment references, while advertised stolen files are hosted on Wasabi. Operators can replace the communications proxy without modifying the victim-facing application. This architecture improves resistance to infrastructure takedowns but still depends on accessible blockchain gateways, a custom proxy, and removable cloud-hosted files. The Rust-based encryptor uses unique per-file XChaCha20 keys protected with Curve25519 and selectively encrypts files, including intermittent encryption of larger files. It applies resource-aware throttling and geographic or language exclusions covering former Soviet and CIS-linked environments and selected Middle Eastern countries. Observed Windows activity includes AnyDesk-based remote control, log clearing and logging suppression, service termination, deletion of backups and Volume Shadow Copies, and removal of scripts and the ransomware executable to reduce forensic evidence. DeadLock changes desktop presentation and supplies ransom notes directing victims to encrypted negotiations. It requests payment in Bitcoin or Monero and offers decryption alongside promises to delete stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against idi pharma, a pharmaceutical and medical-device company, with an associated data leak. The report lists both breach and discovery as October 9, 2026, at 22:51 UTC. Geographic attribution is inconsistent: the target region is ES (Spain), but the company is described as Italian.
Reportedly conducted a ransomware attack against Saber1 Technologies LLC, a US supplier and distributor of machine vision components, industrial cameras, and image processing systems. The incident was discovered on October 9, 2026, at 22:51 UTC. The report provides no technical details about the intrusion or ransomware deployed.
Deadlock lists Saber1 Technologies LLC, a US supplier and distributor of machine vision components, industrial cameras, and image processing systems, as a victim. The listing was discovered on October 9, 2026, but provides no stolen-data details, proof of compromise, ransom demand, or deadline.
Deadlock lists IDI Pharma (idipharma.com) as a victim and claims a data leak, with discovery recorded on October 9, 2026. No stolen-data volume, data categories, ransom demand, deadline, or supporting samples are provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.