Skip to content

DeadLock

DeadLock is a financially motivated, Rust-based Windows ransomware operation first observed in July 2025.

Profile source: Mallory opens in a new tab

DeadLock

Family profile

DeadLock is a financially motivated, Rust-based Windows ransomware operation first observed in July 2025. It employs double extortion, encrypting victim data while threatening to publish exfiltrated information. The operation has affected organizations across Europe, Asia, North America, South America, and Africa, including IT, mining, transportation and logistics, manufacturing, hospitality, and consumer-goods sectors. DeadLock has been deployed by multiple threat actors, including an affiliate associated with the Lynx and INC ransomware ecosystems.

The encryptor uses language- and locale-based geofencing to avoid execution in former Soviet and CIS-linked countries and selected Middle Eastern environments. It can request administrator elevation, enable elevated privileges, terminate security, backup, virtualization, cloud synchronization, remote-access, and other processes and services, clear and disable Windows event logging, remove recovery material and Volume Shadow Copies, and delete itself after encryption. Reported activity also includes abuse of a vulnerable signed antivirus driver to disable endpoint security. DeadLock uses per-file symmetric encryption based on XChaCha20, with key material protected through Curve25519-based cryptography; its encryption design has been assessed as not practically recoverable without the operator-controlled private key. It selectively or partially encrypts larger files to improve speed and appends a victim-specific identifier and the .dlock extension to encrypted files.

DeadLock’s victim recovery workflow is notable for its decentralized architecture. Its self-contained HTML recovery application retrieves chat-proxy configuration and leak-blog content from Polygon smart contracts through public RPC services, uses the Session network for encrypted victim communications, and provides access to stolen files through Wasabi-compatible object storage. This design enables operators to rotate communications infrastructure without redistributing the recovery application and complicates conventional infrastructure takedowns, although it remains dependent on proxies, public blockchain access, messaging-network availability, and hosted storage.

Capabilities

  • Byovd
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Privilege Escalation

Operational record

Recent claims

Reported operators

Threat actors

1 named in public reporting
Contagious Interview

Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.

Exploited software

Vulnerabilities linked to DeadLock

1 CVEs

MITRE ATT&CK

DeadLock in ATT&CK

28 distinct techniques

Reporting

Research mentioning DeadLock

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Aug 10
Malware News

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure - Malware News - Malware Analysis, News and Indicators

Microsoft reported that the DeadLock ransomware operation has emerged as a financially motivated threat using double extortion and a decentralized recovery ecosystem designed to resist disruption. First observed in July 2025, DeadLock had listed more than 80 claimed victims by July 2026, with over half in Europe, and has affected organizations across multiple sectors and regions. Microsoft said the malware has been deployed by multiple groups, including an affiliate tied to the Lynx and INC ransomware ecosystems. The Rust-based encryptor combines common ransomware tradecraft with an unusual communications and leak infrastructure. Microsoft said DeadLock attempts privilege escalation, terminates services and processes, clears event logs, selectively encrypts files, drops ransom notes, and self-deletes, while its recovery workflow relies on a local HTML chat app, the Session messaging network, Polygon smart contracts for configuration and blog data, and Wasabi-hosted stolen files exposed through an S3-compatible browser. The company also described DeadLock's hybrid cryptography using Curve25519 and XChaCha20 with per-file ephemeral keys, assessing the scheme as cryptographically sound and leaving no practical decryption path without the attackers' private key.

Aug 10
Microsoft General

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Security Blog

Aug 1
Malware News

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years - Malware News - Malware Analysis, News and Indicators

Biopharmaceutical company Diater has been listed on the dark-web leak site of the DeadLock ransomware group, in an incident that could expose highly sensitive information tied to patients and healthcare professionals. Reporting indicates the attackers are using a double-extortion model, combining data theft with encryption, and that records retained by Diater for up to 10 years may be at risk of public release. The attackers reportedly claim to have stolen directories containing user folders, documents, QM files, and material linked to EDICOM, although the ransom demand, intrusion date, and full scope of exfiltration have not been disclosed. DeadLock, a ransomware operation first observed in mid-2025 and associated with Russian-origin actors, is known for appending the .dlock extension to encrypted files, adding to concerns that the Diater incident could affect both operational systems and long-term medical data confidentiality.

Aug 1
Data Breaches

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years. - DataBreaches.Net

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Jul 21
Emsisoft

The State of Ransomware in Q2 2026

Jul 20
Cysecurity News

Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts - CySecurity News - Latest Information Security and Hacking Incidents

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.