DeadLock stores read-only dynamic routing configuration in Polygon smart contracts, letting operators update the recovery chat’s proxy URL on-chain without modifying the victim-facing HTML application.
The operation combines Polygon, Session messaging, and Wasabi-hosted stolen files to make victim communication and data-leak workflows more resilient.
Microsoft observed multiple groups deploying DeadLock, including an affiliate previously associated with the Lynx and INC ransomware ecosystems.
DeadLock uses double extortion, combining file encryption with data theft and leak threats, making rapid endpoint containment and tested ransomware response critical for enterprises.
DeadLock ransomware is changing where defenders need to look during an incident. Instead of relying only on conventional web infrastructure, it uses decentralized services that make parts of its communication and extortion workflow more resilient to disruption.
Microsoft reported that DeadLock combines Session messaging with blockchain-backed services. Its recovery chat application queries Polygon smart contracts for current proxy information, which operators can update on-chain.
On affected endpoints, DeadLock stops selected services, disrupts recovery options, encrypts files, drops ransom notes, and changes the desktop wallpaper. Defenders therefore need to address both destructive endpoint activity and decentralized extortion infrastructure.
DeadLock uses blockchain to strengthen its post-compromise infrastructure rather than its encryption process. Its recovery chat application queries Polygon smart contracts through read-only calls to retrieve the current proxy URL, which operators can update on-chain without changing the victim-facing HTML.
This reduces reliance on infrastructure commonly targeted during disruption efforts, such as:
Domains and DNS infrastructure
Centralized hosting
Communication servers
The approach makes parts of DeadLock’s blockchain ransomware infrastructure more resilient to conventional takedowns. However, it still depends on a reachable custom proxy, public Polygon RPC endpoints, and off-chain services such as Wasabi for leaked files. These dependencies leave defenders with potential disruption opportunities.
Top 10 Cybersecurity Challenges for Enterprises
Top enterprise cybersecurity challenges and practical strategies to reduce risk.
What happens after DeadLock reaches a Windows endpoint?
DeadLock prepares Windows systems by deleting backups, stopping selected virtualization-related services, clearing the Recycle Bin, and targeting non-system directories for encryption.
The Rust-based encryptor uses Curve25519 and XChaCha20 with per-file keys. It intermittently encrypts larger files, then adds a victim-specific identifier and .dlock extension, drops ransom notes, changes file icons, and replaces the desktop wallpaper.
DeadLock also limits CPU and memory use, which can keep affected systems relatively responsive while encryption continues.
Signals that deserve immediate investigation
Signal
Why it matters
Response priority
Backup or recovery data deletion
Reduces recovery options before encryption
Critical
Unexpected service termination
May indicate ransomware preparation
High
.dlock extensions and widespread file encryption
Strong indicator of DeadLock encryption activity
Critical
DeadLock ransom notes or wallpaper changes
Strong post-encryption evidence
Critical
Suspicious Polygon RPC activity in incident context
May support infrastructure investigation
Medium
Session communication linked to DeadLock recovery infrastructure
May help investigate victim communication and extortion activity
Medium
Teams investigating DeadLock ransomware should correlate these signals with confirmed endpoint or incident evidence rather than treat Polygon or Session activity alone as malicious.
Double extortion makes encryption only part of the incident
DeadLock uses double extortion, encrypting systems while threatening to publish stolen data. As of July 2026, operators had listed more than 80 compromised organizations, with DeadLock activity affecting sectors including IT, mining, transportation, manufacturing, hospitality, and consumer goods.
Restoring encrypted systems therefore addresses only part of the incident. Security teams should also investigate:
Data staging or unusual outbound transfers
Compromised accounts and administrative credentials
Remote execution or management activity
Access to sensitive repositories
Backup or recovery changes
Related activity across other endpoints
Microsoft has not identified one universal initial-access method for DeadLock. Response teams should base their investigation on evidence from the affected environment rather than assume a specific entry vector.
Containment still begins where the ransomware executes
DeadLock’s decentralized infrastructure complicates disruption, but defenders still need to stop malicious endpoint activity. Organizations responding to DeadLock ransomware should prioritize execution control and endpoint containment while investigating the broader communication and extortion infrastructure.
Microsoft recommends cloud-delivered antivirus protection, EDR in block mode, tamper protection, automated investigation and remediation, Controlled Folder Access, and attack-surface reduction rules, including controls targeting PsExec and WMI activity.
Teams should also:
Isolate affected endpoints when evidence indicates malicious activity.
Protect backup infrastructure and restrict administrative access.
Investigate destructive file and process activity that may precede encryption.
Rotate exposed credentials when evidence indicates compromise.
Preserve forensic evidence before rebuilding affected systems.
Validate backups and recovery procedures before restoring affected environments.
Featured resource
The Cybersecurity Blueprint
Practical cybersecurity blueprint for choosing, implementing, and strengthening the right business security strategy.
Hexnode XDR can support Windows endpoint investigation and endpoint containment during ransomware incidents. Security teams can review process trees and endpoint telemetry, quarantine or delete identified threat files, terminate malicious processes or process trees, and isolate affected endpoints while retaining the XDR management connection.
For ransomware response, teams can use these capabilities to:
Investigate suspicious process and file activity
Quarantine identified malicious files
Terminate malicious processes or process trees
Isolate affected Windows endpoints
Continue remediation through the XDR console
Hexnode UEM can complement these controls with Windows patch and update management, application compliance monitoring, and device compliance policies. These capabilities support patch governance and endpoint compliance, but they do not replace DeadLock-specific threat intelligence, backup protection, identity investigation, network telemetry, or forensic analysis.
FAQs
What is DeadLock ransomware?
DeadLock is a financially motivated ransomware operation first observed in July 2025. It combines file encryption, data-theft extortion, and decentralized infrastructure for victim communication.
Why does DeadLock use Polygon smart contracts?
DeadLock uses Polygon smart contracts to retrieve current proxy configuration, making parts of its communication infrastructure more resilient to conventional takedowns.
Can organizations block Polygon to stop DeadLock?
No. Blocking Polygon alone does not stop DeadLock. Defenders still need endpoint containment, backup protection, credential security, and investigation of ransomware and data-theft activity.
DeadLock’s real lesson is infrastructure diversity
DeadLock shows why disrupting conventional infrastructure may not dismantle an entire DeadLock ransomware extortion operation.
Its use of Polygon-based configuration and Session messaging makes parts of its communication and extortion infrastructure more resilient, although its proxy and external file hosting remain potential disruption points.
Enterprises should focus on what they can control directly: endpoint visibility, rapid containment, protected backups, credential hygiene, and tested recovery procedures.
Keep ransomware from spreading further
Strengthen endpoint visibility, investigation, and containment with Hexnode.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.