Ransomware group “Deadlock” is why this report looks past the leaderboard. A comparatively “quiet” group by named victim volume has introduced blockchain-hosted command and control (C2) and kernel-level EDR evasion... Deadlock's malware retrieves its connection instructions from a public blockchain... Before encryption, it exploits a vulnerable driver to disable endpoint security tools entirely.
DeadLock
DeadLock is a Windows ransomware family first observed in 2025 and associated in reporting with financially motivated operators, including assessments linking the operation to Russian-origin actors.
Profile source: Mallory opens in a new tabDeadLock
Family profile
DeadLock is a Windows ransomware family first observed in 2025 and associated in reporting with financially motivated operators, including assessments linking the operation to Russian-origin actors. It is notable for combining conventional ransomware tradecraft with uncommon blockchain-backed infrastructure. DeadLock uses Polygon smart contracts to store and rotate proxy or command-and-control information, an approach compared to EtherHiding because it makes infrastructure more resilient and harder to disrupt through traditional blocking or takedown measures. Victim communications are conducted through Session, and newer variants use an HTML-based wrapper to facilitate encrypted interaction with the operators.
The malware is written for Windows and has been described as using custom cryptographic implementations, including a custom stream-cipher approach with time-based keys, to encrypt enterprise file types while reducing the risk of system corruption. Encrypted files are commonly renamed with the .dlock extension. Reporting indicates DeadLock evolved from encryption-focused extortion to double extortion, with operators pressuring victims through both file encryption and threats involving stolen data, despite not consistently relying on a traditional public leak site.
Observed intrusions show strong emphasis on defense evasion before encryption. DeadLock operators have used a bring-your-own-vulnerable-driver technique involving CVE-2024-51324 in a Baidu antivirus driver to terminate endpoint security processes at kernel level. Associated scripts have been used to disable security controls, bypass user account control, stop non-whitelisted services, remove backups and volume shadow copies, and otherwise hinder recovery. The malware has also been linked to sandbox-evasion delays prior to encryption.
Operationally, DeadLock campaigns have been observed using legitimate remote administration tooling for persistence and hands-on-keyboard access, particularly AnyDesk, and using Remote Desktop Protocol for lateral movement. PowerShell-based tooling has been used to prepare victim environments for encryption and to impair defensive and recovery mechanisms. Victimology appears opportunistic across multiple industries, with reporting specifically noting activity in Europe and East Asia and incidents affecting sectors handling sensitive data, including healthcare-related organizations.
DeadLock stands out less for victim volume than for its integration of decentralized infrastructure and kernel-level security bypass into ransomware operations, illustrating an evolution toward more resilient command-and-control and more aggressive pre-encryption neutralization of endpoint defenses.
Capabilities
- Byovd
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
- Persistence
- Privilege Escalation
Operational record
Recent claims
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to DeadLock
1 CVEsMITRE ATT&CK
DeadLock in ATT&CK
16 distinct techniquesTechniques
16 techniquesReporting
Research mentioning DeadLock
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years - Malware News - Malware Analysis, News and Indicators
Biopharmaceutical company Diater has been listed on the dark-web leak site of the DeadLock ransomware group, in an incident that could expose highly sensitive information tied to patients and healthcare professionals. Reporting indicates the attackers are using a double-extortion model, combining data theft with encryption, and that records retained by Diater for up to 10 years may be at risk of public release. The attackers reportedly claim to have stolen directories containing user folders, documents, QM files, and material linked to EDICOM, although the ransom demand, intrusion date, and full scope of exfiltration have not been disclosed. DeadLock, a ransomware operation first observed in mid-2025 and associated with Russian-origin actors, is known for appending the .dlock extension to encrypted files, adding to concerns that the Diater incident could affect both operational systems and long-term medical data confidentiality.
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years. - DataBreaches.Net
Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.