DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation
ID: 3a91dde4-5163-508f-97be-9876002b20ed
STIX ID: report--3a91dde4-5163-508f-97be-9876002b20ed
Feed Name: Infosecurity Magazine (News)
DeadLock ransomware has been observed abusing Polygon smart contracts to decentralize storage and rotation of proxy URLs used for command-and-control and relaying encrypted Session messaging; researchers found JavaScript that performs read-only calls to retrieve proxy addresses, linked smart contracts to a single creator wallet that updates proxies over time, and noted fallback RPC endpoints. The malware uses AnyDesk for remote management, PowerShell scripts to stop services and delete shadow copies, renames files with a .dlock extension, and threatens to sell stolen data — a low-volume but technically novel campaign that could be reused by other actors and complicates traditional blocking and detection strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
