logo

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

ID: 106e2b59-d1c7-5271-830e-773109814b51

STIX ID: report--106e2b59-d1c7-5271-830e-773109814b51

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence provides a technical analysis of DeadLock ransomware, an emerging financially motivated operation observed since July 2025 that uses decentralized infrastructure (Polygon smart contracts, Session messenger, Wasabi hosting) to increase resilience of victim communications and data leak operations. The report details pre-encryption behaviors (language geofencing, privilege escalation, service/process termination, event log clearing), a resource-aware throttling and threaded encryption architecture, a sound hybrid cryptographic scheme (Curve25519 ECDH + XChaCha20), per-file footer metadata, deployment of interactive recovery/chat HTML and ransom notes, indicators of compromise, Microsoft Defender detections, and recommended mitigations to defend against this threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.