Malware

INC

Indicators of Compromise 7

MITRE ATT&CK TTPs 25

Source Articles

DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.
bleeping-computer ·3w ago
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware group has adopted a resilient, decentralized infrastructure leveraging Polygon blockchain smart contracts to manage victim communications and data leak operations, making takedown efforts more difficult. The ransomware encrypts files with the '.dlock' extension, uses hybrid encryption (Curve25519 and XChaCha20), and drops an HTML-based interactive recovery note (RECOVERY_CHAT.<UID>.html) that enables end-to-end encrypted chat and access to a blockchain-hosted data leak blog. The HTML note retrieves proxy server addresses via JavaScript interacting with Polygon smart contracts, allowing for censorship-resistant communication. The attackers also use geofencing to avoid certain regions, employ resource throttling, erase logs, and leverage AnyDesk for remote access.
hacker-news ·3w ago
IT threat evolution in Q2 2026. Non-mobile statistics
In Q2 2026, multiple ransomware groups remained active, with Qilin emerging as the most prolific based on victims listed on data leak sites. Microsoft disrupted a malware-signing-as-a-service operation run by the threat actor Fox Tempest, which was used by several ransomware groups including Rhysida, Akira, and Qilin. CISA added a Windows local privilege escalation vulnerability (CVE-2026-33825, BlueHammer) to its KEV catalog due to active exploitation in ransomware attacks. Check Point attributed zero-day exploitation of a critical vulnerability in its Remote Access VPN (CVE-2026-50751) to the Qilin ransomware group. Additionally, the PayoutsKing group was observed using QEMU to deploy hidden Alpine Linux-based virtual machines as a stealthy backdoor technique.
securelist ·3w ago