Skip to content
feed: live
>_ 0dayNews
ransomware
● Breaking

DeadLock Moves Extortion Infra to Polygon Blockchain

DeadLock ransomware has shifted victim comms and data-leak ops to Polygon smart contracts and Session messaging to resist law enforcement seizures.

DeadLock Moves Extortion Infra to Polygon Blockchain
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
airgap airgap · Published · 2 min read

DeadLock ransomware has moved its extortion infrastructure to Polygon blockchain smart contracts and the Session decentralized messaging network. Confirmed: Microsoft Threat Intelligence, corroborated independently by BleepingComputer.

This is not a vulnerability story. No CVE. No software to patch. This is a deliberate architectural change to how DeadLock operates — and it matters for how disruption operations against them would need to work.

What changed

Traditional ransomware operations run centralized infrastructure: C2 servers, data-leak sites, contact portals. Law enforcement seizes those servers, and the operation loses continuity — or at minimum, the pressure on victims collapses while the group rebuilds. That model has been used successfully against LockBit, ALPHV, and others in the last two years.

DeadLock has replaced that surface. According to Microsoft Threat Intelligence: “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.”

Two layers:

Session messaging network — used for direct victim communication. Session is a decentralized, end-to-end encrypted messaging platform with no central server. There is no relay to seize, no account to suspend.

Polygon smart contracts — blockchain-stored and blockchain-delivered resources embedded throughout the extortion lifecycle, including data-leak delivery mechanisms. Polygon is a public, permissionless blockchain. A Polygon smart contract, once deployed, cannot be taken offline by any single party or jurisdiction.

Neither layer has a throat to choke. That is the point.

Confidence

Confirmed: DeadLock is using this infrastructure. Microsoft Threat Intelligence observed it and published findings. BleepingComputer independently confirmed.

Unconfirmed at time of writing: specific Polygon contract addresses, current victim count, whether existing blockchain analytics platforms have flagged these contracts, whether other ransomware groups have already adopted similar infrastructure.

Tactical read — Analysis

The move is a direct response to the centralized-infrastructure problem that burned LockBit and ALPHV. Law enforcement has demonstrated it can pull down C2 and leak sites when given a server to seize. DeadLock has removed that option from the playbook.

Blockchain forensics change the picture somewhat. Polygon is not anonymous. Transaction history is public. Blockchain analytics firms (Chainalysis, TRM Labs, and government equivalents) can trace fund flows and monitor smart contract interactions even without the ability to seize infrastructure. Investigators can see what happened — they just cannot take it offline. That is a different threat model for both sides.

The more significant risk: if this architecture survives a concerted law enforcement effort, expect adoption. Ransomware groups copy what works.

IR and defender notes

If you are investigating a potential DeadLock compromise:

  • Victim-side communications may originate from Session identifiers rather than email or TOR addresses. Standard email-tracing and .onion-monitoring workflows may not apply.
  • Data-leak threats may reference blockchain-hosted content. Exfiltration proof may be stored on-chain or in blockchain-adjacent hosting — not a seizeable web server.
  • Standard takedown-notification workflows (domain seizure, hosting provider contact) likely do not apply to this group’s extortion infrastructure.

No sector-specific targeting indicated at time of writing. DeadLock victim profile is unconfirmed.

Context

DeadLock’s infrastructure shift is operationally separate from other August ransomware activity: Gunra — covered in FBI advisory coverage here — is a conventional RaaS operation exploiting Fortinet firewall flaws, and Storm-1175’s custom StormEncryptor is a state-linked group with different objectives. DeadLock’s change is purely about infrastructure resilience, not a new exploit or a new malware variant.

Watch the blockchain analytics feeds. That is where the next confirmed data point will come from.

Found this useful? Share it.