DeadLock is a financially motivated ransomware family first observed in July 2025 that targets Windows environments and uses double extortion, combining file encryption with threats to publish stolen data. It has been deployed by multiple threat actors, including an affiliate associated with the Lynx and INC ransomware ecosystems, and has affected organizations across Europe, Asia, North America, South America, and Africa, with victim organizations reported in sectors including information technology, mining, transport and logistics, manufacturing, hospitality, and consumer goods.
The malware is notable for its decentralized victim-facing infrastructure. Its recovery workflow uses a local HTML application for negotiations and leak-blog access, the Session messaging network for victim communications, and Polygon blockchain smart contracts to store configuration data and leak-blog content. This design allows operators to rotate proxy information and maintain extortion infrastructure with greater resilience against conventional takedowns. Hosted stolen files have also been associated with Wasabi-compatible storage.
DeadLock is a Rust-based encryptor on Windows that uses selective encryption and resource-aware throttling to reduce operational disruption during execution. Reported behavior includes language- and geography-based execution avoidance, privilege escalation attempts, enabling of high-privilege access rights, termination of security, backup, virtualization, remote-access, and cloud-sync processes and services, deletion of recovery material and shadow copies, clearing and disabling of Windows event logs, modification of desktop wallpaper and file icons, deployment of ransom notes, and self-deletion after encryption. Encrypted files are renamed with a victim-specific identifier and the .dlock extension.
Cryptographically, DeadLock has been reported using a hybrid design based on Curve25519 and XChaCha20 with per-file keys, and its construction has been assessed as not practically decryptable without attacker-held private material. Some reporting also describes custom stream-cipher behavior and selective block encryption for larger files to accelerate impact.
DeadLock has also been linked to defense-evasion tradecraft using bring-your-own-vulnerable-driver techniques. In particular, reporting associates some deployments with abuse of a vulnerable Baidu security driver to disable endpoint protection before ransomware execution, followed by PowerShell-based actions to weaken defenses and remove backups. The family’s combination of mature ransomware functionality, anti-forensics, and blockchain-backed recovery infrastructure distinguishes it from more conventional extortion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The driver contains an improper privilege management flaw (CVE-2024-51324, CVSS 7.8) that lets any low-privilege user shut down protected processes, including EDR. | Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
The malware sleeps for about 50 seconds before encrypting, defeating short sandbox detonation windows.
Another important feature is its implementation of a language- or country-based geofencing to avoid execution in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries.
DeadLock’s standout feature is the way its recovery page uses Polygon blockchain smart contracts as a configuration store. Instead of embedding one server address or relying on a domain that can be seized, the page makes read-only requests to retrieve the current proxy address and the group’s blog content.
Two contracts support this design: one provides the chat proxy location and another stores leak-blog posts.
The page routes victim messages through the Session network, which uses distributed, onion-routed messaging.
Mechanically, a loader drops a legitimate, but vulnerable, antivirus driver... into the target’s Videos directory.
DeadLock emploie la double extorsion : Chiffrement des environnements victimes
The Windows version of the locker uses a PowerShell script to stop services that are not allowlisted and ensure they are not executed automatically after reboot.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family described as a Rust-based encryptor with decentralized recovery infrastructure.
Ransomware used in double-extortion operations, encrypting victim environments and threatening to publish exfiltrated data on the 'DeadLock blog'. The content also describes decentralized communications and leak/distribution infrastructure using Session and blockchain-backed services to improve resilience.
Double-extortion ransomware that steals data and encrypts files. It uses Polygon blockchain-backed configuration retrieval for victim chat infrastructure, the Session network for encrypted communications, and hosts stolen files on Wasabi. On Windows hosts it deletes backups, stops virtualization, empties the Recycle Bin, encrypts non-system directories with per-file XChaCha20 keys protected by Curve25519, appends the '.dlock' extension, drops ransom notes, and changes the desktop wallpaper.
Ransomware that uses double extortion, encrypts files with the .dlock extension, drops text and interactive HTML ransom notes, uses decentralized infrastructure including Session, Polygon smart contracts, and Wasabi-backed leak hosting for resilient victim communications and data leak operations, and includes geofencing, resource-aware throttling, log wiping, shadow copy deletion, and self-deletion features.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.