Ransomware Group DeadLock Utilizes Decentralized Infrastructure for Improved Resilience
The ransomware group DeadLock has been utilizing decentralized infrastructure to enhance victim communications and data leak operations in an effort to boost operational resilience.
According to the Microsoft Threat Intelligence team, DeadLock’s recovery ecosystem integrates the Session messaging network with blockchain-backed services to store and deliver resources used in the extortion process.
Microsoft has observed the ransomware being used by various threat actors, including affiliates for Lynx and INC ransomware.
DeadLock first emerged in July 2025, employing double extortion strategies to encrypt victim environments and apply pressure by threatening to publicly release stolen data. To date, the group has targeted 96 victims, primarily located in Italy, Spain, Poland, Türkiye, and the U.S.
A recent analysis by Group-IB noted that DeadLock has maintained a lower profile compared to other ransomware groups due to its lack of affiliation with known programs and absence of a data leak site. The group’s first victims were not identified until late May 2026.
DeadLock’s attacks involve encrypting files with the “.dlock” extension, changing file icons with a custom “.ico” file, and altering the victim’s desktop wallpaper to display a message instructing them to open the ransom note.
The ransomware employs a selective encryption model to exclude specific directories, file extensions, and names from encryption. It utilizes a hybrid cryptographic design combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption.
Victims are instructed to download the decentralized, end-to-end encrypted messaging app Session to communicate with the attackers and make Bitcoin or Monero payments. The ransom note also promises to provide a security report detailing the network breach and offers security recommendations to prevent future attacks.
![]() |
| HTML recovery chat infrastructure summary |
Another notable feature of DeadLock is its implementation of language- or country-based geofencing to avoid execution in certain regions. It also includes a resource-aware throttling mechanism to maintain system responsiveness during encryption and utilizes AnyDesk for remote control of compromised hosts.
To evade detection and minimize forensic evidence, DeadLock systematically erases logs, disables logging, and utilizes a PowerShell script to stop unauthorized services and delete Volume Shadow Copies on Windows systems.
Additionally, the ransomware creates a batch script to delete its binary and remove itself after successful encryption.

An interesting aspect of DeadLock is its use of an HTML note for direct communication with victims. This interactive web application, titled “RECOVERY_CHAT.
The HTML note facilitates communication between the operator and victims without the need to download the Session app. It utilizes JavaScript code to interact with Polygon smart contracts for decentralized proxy server address rotation, enhancing resilience against takedown efforts.
The ransomware’s recovery chat page also provides access to a data leak blog hosted on the Polygon blockchain, enabling victims to browse leaked files securely. The threat actor utilizes two wallet addresses for payments.
Microsoft noted that DeadLock’s decentralized infrastructure represents a significant evolution in ransomware communication channels, posing challenges for takedown efforts. The use of smart contracts for proxy server addresses allows the operator to maintain communication continuity even in the face of disruptions.


