Microsoft details DeadLock ransomware's decentralized recovery and leak infrastructure

Microsoft details DeadLock ransomware's decentralized recovery and leak infrastructure

Microsoft says DeadLock ransomware uses blockchain, Session chat and cloud storage to make extortion infrastructure harder to disrupt.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Aug 11, 2026

Microsoft Threat Intelligence has published a technical breakdown of DeadLock, an emerging ransomware operation that pairs conventional double-extortion tactics with a more resilient recovery and leak infrastructure. The report, published August 10, says the group has been active since July 2025 and had listed more than 80 compromised organizations on its leak site by July 2026, with more than half of the claimed victims in Europe.

The notable development is not simply another encryptor. Microsoft says DeadLock's victim recovery flow uses a self-contained HTML application that can handle encrypted chat, a data-leak blog and file browsing without a traditional backend server. The page retrieves some configuration through Polygon blockchain smart contracts, uses the Session messaging network for victim-operator communication and can expose stolen files through Wasabi S3-compatible storage. That combination gives the operators several places to recover from takedown attempts, even though the system still depends on reachable proxy, RPC and storage services.

Why defenders should care

DeadLock's malware also shows familiar but operationally important ransomware behavior. Microsoft says the analyzed encryptor can terminate processes and disable services that interfere with file access or recovery, including Windows Defender, Volume Shadow Copy and backup-related services. It also attempts privilege expansion when running with administrator rights, empties the recycle bin, brands encrypted files with a custom icon and deploys both text and HTML recovery notes after encryption.

The report says the encryptor includes a resource-aware throttling mechanism intended to keep systems responsive during encryption, a detail that may help attacks progress without immediately drawing attention from users or monitoring based on system instability. Microsoft also observed language and country-based geofencing that causes the malware to exit in environments associated with Russia, Ukraine, Belarus, several other former Soviet or CIS-linked countries and selected Middle Eastern locales, a pattern often seen in ransomware ecosystems operating from or near those regions.

What changed

The defensive implication is that takedown work is becoming more complicated. Older ransomware playbooks often focused on domains, negotiation portals and leak sites that could be disrupted as web infrastructure. DeadLock's design moves pieces of that workflow into decentralized or easily replaceable services, while still leaving defenders with indicators of compromise and behavior patterns to hunt. Microsoft published hashes, domains, detection names and mitigation guidance for Defender customers, and it says DeadLock has been deployed by multiple groups, including an affiliate connected to the Lynx and INC ransomware ecosystems.

For security teams, the practical response remains grounded: harden identity, limit administrative privileges, monitor for service disruption, protect backups from the same administrative plane as production systems and watch for ransomware staging before encryption begins. The fresh research is a reminder that ransomware innovation is increasingly about operations and recovery infrastructure, not only the cryptography used to lock files.

Sources

Cover image: Christoph Scholz, source, licensed under BY-SA.

Comments (0)

Leave a Comment

Loading comments...