Microsoft says DeadLock has shifted its extortion setup onto Session and Polygon smart contracts, using blockchain-hosted leak pages to make its pressure-and-leak infrastructure harder to disrupt. The group’s tooling is also being used by multiple threat actors, including affiliates for Lynx and INC ransomware.
Instead of relying on one leak site or one chat server, DeadLock now spreads the contact path and leak-page pointers across decentralized services. That means removing a single page or suspending a single account may not break the negotiation or publication flow, because the pointers and messaging can survive ordinary takedowns.
For incident responders and ransomware negotiators, the map changes from host removal to infrastructure resilience. If your containment playbook depends on taking down one server or one domain, DeadLock shows how extortion can keep moving after that choke point disappears.
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Security Blog
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.