Microsoft Threat Intelligence researchers have identified a novel technique employed by the DeadLock ransomware group, which is now using Polygon blockchain smart contracts to host and deliver resources used throughout its extortion process, making the infrastructure significantly harder for law enforcement to disrupt.
In an analysis published August 11, Microsoft detailed how DeadLock combines the Session encrypted messaging network with blockchain-backed services to store communications and data leak infrastructure. “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the researchers wrote.
DeadLock, first detected in July 2025, employs double-extortion tactics that encrypt victim networks while threatening to publicly release exfiltrated data. The group has claimed 96 victims to date, with the majority concentrated in Italy, Spain, Poland, Turkey, and the United States. Microsoft observed the ransomware being deployed by multiple threat actors, including affiliates linked to Lynx and INC ransomware operations.
The use of decentralized blockchain infrastructure represents a significant evolution in ransomware operations. By anchoring key communications and leak site resources to Polygon smart contracts, the group creates a system that cannot be easily taken down through conventional server seizures or domain takedowns. The smart contracts effectively serve as resilient distribution points for stolen data and negotiation portals that persist even when individual infrastructure components are removed.
Singapore-based cybersecurity firm Group-IB, which published its own analysis of DeadLock earlier in January, noted that the group has managed to maintain a relatively low profile compared to other ransomware operations despite its growing victim count. The combination of decentralized infrastructure and cross-affiliate deployment through Lynx and INC ransomware channels has helped DeadLock expand its reach without drawing the same level of attention as louder competitors.
The adoption of blockchain technology by ransomware operators follows a broader trend of criminal groups leveraging decentralized tools to harden their operations. Similar patterns have been observed with cryptocurrency mixing services and decentralized hosting, but the direct use of smart contracts to manage extortion workflows marks a new level of technical sophistication.
Microsoft recommends that organizations defend against DeadLock by implementing robust network segmentation, maintaining immutable backups stored offline, monitoring for indicators of compromise associated with Lynx and INC ransomware affiliates, and ensuring all systems are patched against known exploited vulnerabilities. The firm continues to track DeadLock as it evolves its capabilities and expands its affiliate network. The Hacker News
discussion