DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
ID: 7d0de92e-bf1a-57ec-b309-88496ea8f71e
STIX ID: report--7d0de92e-bf1a-57ec-b309-88496ea8f71e
Feed Name: securityonline.info
Threat Score
**DeadLock ransomware:** Group-IB discovered a low-profile but technically sophisticated ransomware strain (DeadLock) that leverages Polygon smart contracts to publish and rotate proxy server addresses for resilient, decentralized C2, uses PowerShell to disable backups/security while whitelisting AnyDesk for remote access, communicates via the decentralized Session messenger, and has evolved ransom notes to threaten data theft and extortion services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
