
Microsoft details DeadLock extortion tactics
Microsoft Threat Intelligence has analyzed DeadLock, a Rust-based ransomware operation that uses decentralized infrastructure for victim communications and data leaks. The threat utilizes double extortion tactics against organizations across multiple global sectors.
Why it matters
The use of blockchain and decentralized messaging makes the attacker's infrastructure more resilient to takedown efforts by authorities. This increases the difficulty of disrupting recovery and negotiation processes for infected organizations.
The details
- Uses Polygon blockchain and Session messenger for censorship-resistant communication.
- Implements resource-aware throttling to keep infected systems responsive during encryption.
- Employs geofencing to avoid targets in CIS-linked and select Middle Eastern countries.
Show entities and relationshipsHide entities and relationships
In this article
Countries
Products
Topics
Companies
Key connections
Microsoft owns Microsoft Defender for Cloud Apps
Microsoft develops and owns Microsoft Defender for Cloud Apps.
Microsoft is related to DeadLock
Microsoft Threat Intelligence tracks and analyzes DeadLock ransomware.
Wasabi Technologies is related to DeadLock
DeadLock operators utilize Wasabi cloud storage to host leaked files.
Microsoft Defender is related to DeadLock
Microsoft Defender detects and mitigates DeadLock ransomware.
DeadLock targets Windows operating systems and alters Windows event logs and registry keys.
DeadLock routes victim communications through the Session decentralized messaging network.
Show 9 more connectionsShow fewer connections
DeadLock stores recovery chat configuration and data leak blog content on the Polygon blockchain.
Polygon is built with Blockchain
Polygon is built on blockchain technology.
DeadLock uses Curve25519
DeadLock uses Curve25519 elliptic-curve cryptography for asymmetric key exchange.
DeadLock uses XChaCha20 symmetric cipher for file encryption.
DeadLock uses XSalsa20-Poly1305
DeadLock uses XSalsa20-Poly1305 authenticated encryption for key wrapping.
DeadLock uses Ed25519 signatures for Session chat message authentication.
Affiliates of the Lynx ransomware ecosystem deploy DeadLock ransomware.
Affiliates of the INC ransomware ecosystem deploy DeadLock ransomware.
Microsoft owns Microsoft Defender XDR
Microsoft develops and operates Microsoft Defender XDR
Related events
Microsoft Threat Intelligence Analyzes DeadLock Ransomware Operation
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.