DeadLock is a financially motivated ransomware operation first observed in July 2025. It is notable for combining conventional double-extortion ransomware tradecraft with an unusually decentralized victim-facing infrastructure designed to improve resilience against takedowns. The operation encrypts victim environments and threatens to publish exfiltrated data through its leak platform, while using blockchain-backed services and the Session messaging network to support victim communications, leak hosting, and negotiation workflows. DeadLock has also been described as a Rust-based encryptor with decentralized recovery infrastructure. By mid-2026, DeadLock had become one of the more active ransomware brands, ranking among the top groups by published victim volume. Reported victims were concentrated in Europe, with additional victims across Asia, North America, South America, and Africa. Countries repeatedly associated with claimed victims include Italy, Spain, Poland, Türkiye, the United States, the Philippines, the United Kingdom, and Colombia. Observed victim sectors include information technology, manufacturing, transport and logistics, hospitality, consumer goods, mining, and healthcare-related organizations such as laboratories and biopharmaceutical firms. DeadLock uses a double-extortion model that combines file encryption with data theft and leak threats. Its malware employs selective encryption and geofencing to avoid execution in former Soviet and CIS-linked countries and certain Middle Eastern locales. Reported behaviors include privilege elevation, enabling high-value privileges, terminating processes and services, deleting backups and shadow copies, clearing or disabling event logging, dropping ransom notes, changing desktop wallpaper, and self-deletion after execution. The encryptor uses a hybrid cryptographic design based on Curve25519 and XChaCha20, with partial or intermittent encryption for larger files to accelerate impact while preserving irrecoverability. A distinguishing feature of DeadLock is its decentralized recovery and extortion ecosystem. The operation uses local HTML-based ransom interfaces that function as self-contained applications for encrypted chat, leak-blog access, and browsing stolen files. Configuration data and blog content are retrieved through Polygon smart contracts and related blockchain-backed mechanisms, while encrypted victim communications are conducted over Session. This architecture reduces dependence on conventional domains and centralized web servers, complicating disruption efforts, although it still relies on supporting proxy and hosting components. Microsoft observed DeadLock being deployed by multiple groups rather than a single tightly bounded operator set. One observed deployer was an affiliate associated with the Lynx and INC ransomware ecosystems, indicating overlap with broader affiliate-driven ransomware activity. DeadLock therefore appears to function as a ransomware brand or capability used by more than one threat cluster. Known aliases are limited to DeadLock and capitalization variants such as Deadlock.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group that rose to third place in July 2026 with 10% of published attacks and 97 reported victims.
Emerging financially motivated ransomware group using decentralized infrastructure combining the Session messaging network and blockchain-backed services to support extortion operations, leak hosting, and negotiations. It uses double extortion, encrypting victim environments and threatening to publish exfiltrated data on the DeadLock blog.
A ransomware group first observed in July 2025 that uses blockchain-based techniques to rotate command-and-control proxy addresses and legitimate remote management tools.
Conducting double-extortion ransomware attacks using data theft, leak-site pressure, and file encryption, while leveraging decentralized infrastructure including Polygon blockchain-backed configuration retrieval and the Session network for victim communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.