DeadLock Moves Extortion Behind Blockchain Pointers

Microsoft says DeadLock has shifted its extortion setup onto Session and Polygon smart contracts, using blockchain-hosted leak pages to make its pressure-and-leak infrastructure harder to disrupt. The group’s tooling is also being used by multiple threat actors, including affiliates for Lynx and INC ransomware. Instead of relying on one leak site or one chat server, DeadLock now spreads the contact path and leak-page pointers across decentralized services. That means removing a single page or suspending a single account may not break the negotiation or publication flow, because the pointers and messaging can survive ordinary takedowns. For incident responders and ransomware negotiators, the map changes from host removal to infrastructure resilience. If your containment playbook depends on taking down one server or one domain, DeadLock shows how extortion can keep moving after that choke point disappears.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: DeadLock Moves Extortion Behind Blockchain Pointers

Sources