DeadLock Uses Polygon to Build Resilient Ransomware Infrastructure
DeadLock is an emerging, financially motivated ransomware operation first observed by Microsoft in July 2025. It uses double extortion, encrypting victim systems while threatening to publish stolen data. The group matters because its recovery and extortion ecosystem combines the Session messaging network with blockchain-backed services, reducing its reliance on conventional domains and centralized servers that authorities can seize or disable. Microsoft has also seen DeadLock deployed by multiple groups, including an affiliate linked to the Lynx and INC ransomware ecosystems.
In an Aug. 10, 2026 analysis, Microsoft Threat Intelligence said DeadLock had listed more than 80 compromised organizations on its leak site as of July, with over half in Europe. Two smart contracts on Polygon store the current proxy URL and blog posts, while the recovery page rotates through six public RPC endpoints for redundancy. Session handles encrypted victim communications, and stolen files can be hosted on Wasabi’s S3-compatible service. The design improves resilience, though it still depends on reachable proxies, RPC services and off-chain storage.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.