DeadLock Uses Decentralized Services to Keep Extortion Alive

Microsoft says DeadLock ransomware has been active since July 2025 and has already had more than 80 organizations posted on its leak site by July 2026. The group stands out less for its Rust-based encryptor than for the recovery and extortion system around it: victim communications, negotiations, and leak hosting are built on Session messaging and blockchain-backed services. In plain terms, DeadLock spreads the parts of the operation that keep pressure on a victim across decentralized services instead of one fixed chat site or leak server. If one host or site is disrupted, the rest can still carry the negotiation and publication workflow, so takedowns are less likely to end the extortion cycle. For defenders, the map matters: this is an extortion-resilience story, not just a malware story. If your response playbook assumes one leak site or one chat channel can break the operation, DeadLock shows how that pressure can survive partial disruption and keep moving.

Part of the PlainSec briefing for 2026-08-10

Editions

Sources