'Imagination the limit': DeadLock ransomware gang using smart contracts to hide their work
ID: 76ba5128-14f1-56aa-91cf-f6fad4824acc
STIX ID: report--76ba5128-14f1-56aa-91cf-f6fad4824acc
Feed Name: The Register (Security)
Threat Score
Researchers at Group-IB have observed the DeadLock ransomware group using Polygon smart contracts to hide and frequently rotate proxy/C2 addresses, combined with an HTML wrapper directing victims to the Session messenger; the group follows an encryption-only extortion model (no DLS) and leverages techniques such as BYOVD and EDR-killing to evade detection, representing a sophisticated blockchain-based evasion trend.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
