DeadLock ransomware has raised the stakes in the ongoing battle between cybercriminals and security teams. First reported in July 2025, DeadLock ransomware uses the Polygon blockchain to store its command-and-control (C2) configuration, creating new challenges for defenders and law enforcement. This tactic, combined with a resilient Rust-based encryptor, has allowed the threat to hit over 80 organisations by July 2026, with more than half of these victims located in Europe.
DeadLock ransomware: timeline and scope of attacks
The emergence of DeadLock ransomware was first documented in July 2025. Within a year, its impact had spread worldwide, with victims spanning IT, mining, transport, manufacturing, hospitality, consumer goods and other sectors. The group’s leak site had listed over 80 victims by July 2026, demonstrating a broad and sustained campaign. The majority of these attacks targeted European organisations, including those in the UK, suggesting a particular regional risk.
Microsoft analysts note that DeadLock’s operators favour a strategy of double extortion. This means that, in addition to encrypting files and demanding a ransom for decryption, the attackers also threaten to publish stolen data publicly if their demands are not met. This approach increases pressure on victims to pay and magnifies the risk of reputational harm and regulatory consequences.
- First observed: July 2025
- Victims listed: Over 80 by July 2026
- Geographic focus: Over half in Europe, including the UK
- Industry sectors affected: IT, mining, transport, manufacturing, hospitality, consumer goods
How DeadLock ransomware operates: technical details and tactics
DeadLock ransomware stands out for both its technical sophistication and its operational resilience. At its core is a Rust-based encryptor, chosen for its cross-platform capability and resistance to analysis. The group’s approach to persistence and evasion, however, is what has drawn most attention from security researchers.
Use of the Polygon blockchain for C2 configuration
One of DeadLock’s most notable innovations is its use of the Polygon blockchain to store its C2 configuration. Traditional ransomware groups rely on websites or domains for C2 infrastructure, which can be seized or blocked by authorities. In contrast, DeadLock embeds its configuration data in blockchain transactions, making it extremely difficult to disrupt. The blockchain is decentralised and immutable, so once the configuration is written, it cannot be removed or altered by defenders or law enforcement.
- Configuration data is published on the Polygon blockchain
- Victim machines query the blockchain to obtain C2 information
- This method prevents takedown by traditional means, such as domain blacklisting
This blockchain-based approach also helps DeadLock operators maintain their operations even if security teams attempt to block known C2 endpoints, as new instructions can be published on-chain and rapidly propagated to infected hosts.
Attack chain and impact on victims
While researchers did not identify a single method of initial access, DeadLock ransomware is capable of targeting a specific directory, requesting administrative privileges, and systematically disabling defences that might slow or stop the encryption process. Key features include:
- Deletion of recovery materials to prevent restoration from backups
- Targeting and disabling of backup services, security tools, remote access and cloud sync processes
- Clearing event logs to hinder forensic investigation
- Leaving a browser-based recovery page for ransom negotiation and payment
These tactics are designed to maximise victim disruption, delay containment and hinder forensic analysis. By targeting both backups and logging, DeadLock increases the likelihood that victims will have no choice but to engage with the attackers.
Double extortion and public pressure
DeadLock’s double extortion model amplifies the threat. Victims must not only contend with inaccessible data, but also the risk of sensitive information being leaked. The ransomware operators have maintained a steady public-pressure campaign by listing victims on their leak site, which further incentivises payment.
The group’s success is reflected in the diversity and number of its victims, as well as its ability to maintain operations despite growing public awareness and defensive efforts.
Current exploitation status and defensive challenges
As of August 2026, DeadLock ransomware remains an active and evolving threat. Its use of the Polygon blockchain for C2 configuration has made traditional takedown attempts largely ineffective. Security researchers have warned that the malware’s ability to delete backups, disable security and synchronisation tools, and clear logs makes rapid containment especially difficult. Organisations without robust, offline backup strategies and incident response protocols are at heightened risk.
The sustained campaign across multiple sectors and the group’s adaptive infrastructure suggest that DeadLock will remain a significant concern for European and UK organisations in the foreseeable future.
Why DeadLock ransomware matters for UK and European organisations
DeadLock ransomware’s innovative use of the Polygon blockchain for C2 infrastructure marks a significant evolution in ransomware tactics. By making takedowns almost impossible, the group can continue its operations with little fear of disruption. The focus on Europe, including the UK, means local organisations are at particular risk, especially if they rely on online or cloud-based backups.
Practical steps for organisations in response to DeadLock
- Assess and strengthen backup strategies, prioritising offline and immutable backups
- Review and restrict administrative privileges to minimise ransomware impact
- Enhance monitoring for unusual process and network activity, including blockchain queries
- Develop incident response plans to quickly identify and contain ransomware attacks
Given DeadLock’s double extortion tactics and focus on backup and security tool disruption, specific and proactive preparation is essential.
Originally reported by cybersecuritynews.com.






