Executive Summary
In July 2025, the DeadLock ransomware group emerged, employing double extortion tactics to encrypt victim environments and threaten the public release of exfiltrated data. Notably, DeadLock utilizes decentralized infrastructure, combining the Session messaging network with blockchain-backed services, specifically Polygon smart contracts, to store and deliver resources throughout the extortion process. This approach enhances the group's operational resilience by making their infrastructure harder to disrupt. As of August 2026, DeadLock has claimed 96 victims, primarily in Italy, Spain, Poland, Türkiye, and the U.S.
The group's innovative use of blockchain technology for command-and-control operations signifies a concerning trend in ransomware tactics. By leveraging decentralized platforms, DeadLock demonstrates an evolution in cybercriminal strategies, posing new challenges for traditional defense mechanisms and takedown efforts.
Why This Matters Now
The DeadLock ransomware group's use of decentralized infrastructure, particularly Polygon smart contracts, represents a significant evolution in cybercriminal tactics, making their operations more resilient and challenging to disrupt. This trend underscores the urgent need for organizations to adapt their cybersecurity strategies to address these sophisticated methods.
Attack Path Analysis
The DeadLock ransomware attack begins with the exploitation of a known vulnerability in a legitimate driver to disable endpoint detection and response (EDR) systems, facilitating initial compromise. Following this, the attackers escalate privileges by deploying a PowerShell script to stop non-allowlisted services and delete Volume Shadow Copies, ensuring persistence and control. They then move laterally within the network using remote management tools like AnyDesk to access and control additional systems. For command and control, DeadLock utilizes decentralized infrastructure, including the Session messaging network and blockchain-backed services, to manage communications and data leak operations. Data exfiltration is achieved by encrypting files and threatening to publicly release exfiltrated data to pressure victims into paying the ransom. The impact culminates in the encryption of victim environments, modification of file icons and desktop wallpapers, and the dropping of ransom notes instructing victims to contact the attackers via the Session application.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of a known vulnerability in a legitimate driver to disable endpoint detection and response (EDR) systems, facilitating initial compromise.
Related CVEs
CVE-2024-51324
CVSS 3.8Improper Privilege Management vulnerability in Baidu Antivirus driver 'BdApiUtil.sys' allows attackers to disable endpoint detection and response (EDR) processes.
Affected Products:
Baidu Baidu Antivirus – All versions up to 2024
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Data Encrypted for Impact
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Application Layer Protocol: Web Protocols
Web Service: Bidirectional Communication
Impair Defenses: Disable or Modify Tools
Indicator Removal on Host: Clear Windows Event Logs
Remote Access Software
User Execution: Malicious File
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malicious Software Prevention
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
DeadLock ransomware targeting financial institutions poses severe risks through lateral movement, data exfiltration, and blockchain-resistant extortion infrastructure bypassing traditional takedown methods.
Health Care / Life Sciences
Healthcare organizations face critical vulnerabilities from DeadLock's selective encryption, east-west traffic exploitation, and HIPAA compliance violations through compromised patient data systems.
Information Technology/IT
IT sector experiences heightened exposure through Kubernetes environments, cloud infrastructure targeting, and sophisticated egress security bypasses enabling persistent command and control operations.
Government Administration
Government entities encounter severe threats from DeadLock's decentralized recovery infrastructure, encrypted traffic exploitation, and zero trust segmentation vulnerabilities compromising critical operations.
Sources
- DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupthttps://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.htmlVerified
- DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructurehttps://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/Verified
- DeadLock Ransomware: Smart Contracts for Malicious Purposeshttps://www.group-ib.com/blog/deadlock-ransomware-polygon-smart-contracts/Verified
- DeadLock ransomware uses smart contracts to evade defendershttps://www.theregister.com/security/2026/01/14/deadlock-ransomware-uses-smart-contracts-to-evade-defenders/5034920Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to the DeadLock ransomware incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation may still occur, CNSF would likely limit the attacker's ability to disable security controls across the network.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting unauthorized service modifications.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the attacker's ability to move laterally by restricting unauthorized internal communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by monitoring and restricting unauthorized communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies.
While initial encryption may occur, the attacker's ability to propagate the impact across the network would likely be limited.
Impact at a Glance
Affected Business Functions
- IT Operations
- Data Management
- Customer Service
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of sensitive customer and corporate data due to double extortion tactics.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of ransomware within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce East-West Traffic Security to monitor and secure internal communications, reducing the risk of lateral movement.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads, enhancing initial compromise defenses.



