Particle.news

DeadLock Ransomware Uses Session and Polygon Smart Contracts to Harden Extortion Infrastructure

Microsoft says an HTML recovery chat queries on-chain proxy addresses so operators can host leaks and change proxies without relying on takedown-prone domains.

Overview

  • Microsoft published its analysis on Tuesday, August 11, 2026, confirming DeadLock combines the end-to-end encrypted Session network with Polygon smart contracts to run an interactive HTML recovery chat and decentralize leak hosting.
  • The HTML file is a self-contained single-page app that provides encrypted chat, a paginated data-leak blog and a file browser, and it reads proxy URLs from Polygon contracts so operators can rotate proxies without touching victim-facing domains.
  • DeadLock has claimed 96 victims, mostly in Italy, Spain, Poland, Türkiye and the United States, and Microsoft observed multiple affiliates, including groups linked to Lynx and INC, deploying the locker.
  • The malware uses selective encryption with a .dlock extension, Curve25519 plus XChaCha20 per-file keys, language and country geofencing to skip CIS and select Middle Eastern environments, and defense-evasion features such as AnyDesk access, shadow-copy deletion, log erasure, resource-aware throttling and self-deletion.
  • The shift from central leak sites to blockchain-backed proxies and on-chain pointers raises new challenges for takedown and attribution, so Microsoft recommends stronger endpoint protections, EDR in block mode, controlled folder access and automated remediation to limit damage and speed recovery.