DeadLock is a Rust-based ransomware family targeting Windows systems, first observed in July 2025. Its financially motivated operators use double extortion, combining file encryption with threats to publish stolen information. Multiple threat actors have deployed DeadLock, including an affiliate associated with the Lynx and INC ransomware ecosystems. Targeted industries include information technology, mining, transportation and logistics, manufacturing, hospitality, and consumer goods. Claimed victims span multiple continents, with a substantial concentration in Europe.
The encryptor uses Curve25519-based key exchange and per-file XChaCha20 encryption, with selective and partial encryption strategies for different file sizes. Resource-aware throttling pauses new encryption work when CPU or memory utilization exceeds configured thresholds. DeadLock requests administrator elevation, enables privileged access rights, terminates processes, disables services, removes recovery material, and clears or disables Windows event logs. It excludes selected files and directories to preserve system operability, applies language-based execution exclusions, and deletes its executable after encryption. DeadLock deployments have also used vulnerable signed drivers to terminate endpoint security processes through bring-your-own-vulnerable-driver techniques.
DeadLock's distinctive victim-facing recovery infrastructure is a self-contained HTML application providing encrypted chat, a leak blog, and access to stolen files. It retrieves a messaging proxy address and leak-blog content through read-only calls to Polygon smart contracts, uses redundant public RPC gateways, relays victim communications through the Session network, and accesses leaked files in Wasabi-compatible object storage. Operators can change the messaging proxy without redistributing the recovery application. This modular architecture increases resistance to infrastructure disruption but still depends on accessible RPC services, a functioning proxy, Session availability, and cloud-hosted files. The blockchain functionality supports post-compromise extortion rather than establishing a mechanism for initial payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The driver contains an improper privilege management flaw (CVE-2024-51324, CVSS 7.8) that lets any low-privilege user shut down protected processes, including EDR. | Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
For defense evasion and minimizing forensic evidence, it systematically erases logs and disables logging via Registry manipulation to prevent recording future events.
The malware sleeps for about 50 seconds before encrypting, defeating short sandbox detonation windows.
Another important feature is its implementation of a language- or country-based geofencing to avoid execution in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries.
DeadLock’s standout feature is the way its recovery page uses Polygon blockchain smart contracts as a configuration store. Instead of embedding one server address or relying on a domain that can be seized, the page makes read-only requests to retrieve the current proxy address and the group’s blog content.
Two contracts support this design: one provides the chat proxy location and another stores leak-blog posts.
The page routes victim messages through the Session network, which uses distributed, onion-routed messaging.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
it includes a "resource-aware throttling mechanism" that ensures system responsiveness as the encryption process is underway and pauses it when memory usage exceeds 29% or CPU load exceeds 70%, while relying on AnyDesk for remote control of compromised hosts.
Attackers claim to have exfiltrated over 13,400 GB of data across the period... Attackers claimed to have stolen a total of 13,405.22 GB.
The Gentlemen ransomware [was] deployed... DeadLock applies a similar mechanism to victim communications after encryption.
The Windows version of the locker uses a PowerShell script to stop services that are not allowlisted and ensure they are not executed automatically after reboot.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as background research documenting another ransomware family's use of a different Baidu BdApiUtil driver sample. The article does not establish an operational relationship with IronChain.
Ransomware mentioned as a comparison because it uses a different Baidu BdApiUtil driver sample. The reference does not establish a relationship between DeadLock and IronChain beyond their use of the same driver family.
An extortion-focused ransomware operation whose victim-facing application uses Polygon smart contracts to obtain a messaging-proxy address and leak-blog content. The article does not establish that its encryptor is delivered through EtherHiding.
A newly discussed ransomware/extortion operation with a modular victim-facing recovery and extortion workflow. Its portal uses Polygon smart contracts for configuration and leak-blog retrieval, Session for encrypted victim communications, and Wasabi-compatible object storage for leaked files, making individual infrastructure layers more replaceable and resistant to a single takedown.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.