Malware
INC
Indicators of Compromise 7
MITRE ATT&CK TTPs 25
T1014 T1021.006 T1027 T1056.001 T1059.001 T1070.001 T1071.001 T1083 T1090 T1105 T1133 T1203 T1212 T1213 T1484.001 T1486 T1490 T1491.001 T1542.001 T1543.003 T1548.002 T1552.001 T1566 T1574.002 T1588.001
Rootkit
Defense Evasion
Windows Remote Management
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Clear Windows Event Logs
Defense Evasion
Web Protocols
Command And Control
File and Directory Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
External Remote Services
Persistence
Exploitation for Client Execution
Execution
Exploitation for Credential Access
Credential Access
Data from Information Repositories
Collection
Group Policy Modification
Defense Evasion
Data Encrypted for Impact
Impact
Inhibit System Recovery
Impact
Internal Defacement
Impact
System Firmware
Persistence
Windows Service
Persistence
Bypass User Account Control
Privilege Escalation
Credentials In Files
Credential Access
Phishing
Initial Access
DLL Side-Loading
Persistence
Malware
Resource Development
Source Articles
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.
bleeping-computer ·3w ago
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware group has adopted a resilient, decentralized infrastructure leveraging Polygon blockchain smart contracts to manage victim communications and data leak operations, making takedown efforts more difficult. The ransomware encrypts files with the '.dlock' extension, uses hybrid encryption (Curve25519 and XChaCha20), and drops an HTML-based interactive recovery note (RECOVERY_CHAT.<UID>.html) that enables end-to-end encrypted chat and access to a blockchain-hosted data leak blog. The HTML note retrieves proxy server addresses via JavaScript interacting with Polygon smart contracts, allowing for censorship-resistant communication. The attackers also use geofencing to avoid certain regions, employ resource throttling, erase logs, and leverage AnyDesk for remote access.
hacker-news ·3w ago
IT threat evolution in Q2 2026. Non-mobile statistics
In Q2 2026, multiple ransomware groups remained active, with Qilin emerging as the most prolific based on victims listed on data leak sites. Microsoft disrupted a malware-signing-as-a-service operation run by the threat actor Fox Tempest, which was used by several ransomware groups including Rhysida, Akira, and Qilin. CISA added a Windows local privilege escalation vulnerability (CVE-2026-33825, BlueHammer) to its KEV catalog due to active exploitation in ransomware attacks. Check Point attributed zero-day exploitation of a critical vulnerability in its Remote Access VPN (CVE-2026-50751) to the Qilin ransomware group. Additionally, the PayoutsKing group was observed using QEMU to deploy hidden Alpine Linux-based virtual machines as a stealthy backdoor technique.
securelist ·3w ago