logo

'Imagination the limit': DeadLock ransomware gang using smart contracts to hide their work

ID: 76ba5128-14f1-56aa-91cf-f6fad4824acc

STIX ID: report--76ba5128-14f1-56aa-91cf-f6fad4824acc

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers at Group-IB have observed the DeadLock ransomware group using Polygon smart contracts to hide and frequently rotate proxy/C2 addresses, combined with an HTML wrapper directing victims to the Session messenger; the group follows an encryption-only extortion model (no DLS) and leverages techniques such as BYOVD and EDR-killing to evade detection, representing a sophisticated blockchain-based evasion trend.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.