logo

DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts

ID: 7d0de92e-bf1a-57ec-b309-88496ea8f71e

STIX ID: report--7d0de92e-bf1a-57ec-b309-88496ea8f71e

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-16

Date Updated: 2026-04-23

Author: Ddos

...
...

**DeadLock ransomware:** Group-IB discovered a low-profile but technically sophisticated ransomware strain (DeadLock) that leverages Polygon smart contracts to publish and rotate proxy server addresses for resilient, decentralized C2, uses PowerShell to disable backups/security while whitelisting AnyDesk for remote access, communicates via the decentralized Session messenger, and has evolved ransom notes to threaten data theft and extortion services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.