CyberSecurityBoardThreat Intel · CVEs · Products
Malware

DeadLock Ransomware Abuses Polygon Smart Contracts for Resilient Extortion Infrastructure

August 11, 2026

Microsoft Threat Intelligence has uncovered that the DeadLock ransomware group is leveraging decentralized infrastructure, including Polygon smart contracts and the Session messaging app, to make its extortion operations more resilient to takedown efforts. First detected in July 2025, DeadLock employs double extortion tactics, encrypting victim files and threatening to leak data unless a ransom is paid in Bitcoin or Monero. As of August 2026, the group has claimed 96 victims, primarily in Italy, Spain, Poland, Türkiye, and the U.S.

The ransomware encrypts files with a “.dlock” extension, changes file icons, and alters the victim’s wallpaper to display a ransom note. It uses a hybrid cryptographic design combining Curve25519 and XChaCha20, and includes geofencing to avoid execution in former Soviet and CIS-linked countries. The malware also features resource-aware throttling to maintain system responsiveness, and uses AnyDesk for remote control. It erases logs, disables logging via Registry manipulation, and deletes Volume Shadow Copies to evade forensics.

A notable aspect is the HTML ransom note (“RECOVERY_CHAT..html”) that acts as a self-contained web application, providing end-to-end encrypted chat, a data leak blog, and a file browser without a traditional backend. This HTML file interacts with Polygon smart contracts to rotate proxy server addresses, making the infrastructure censorship-resistant. The data leak blog is hosted on the Polygon blockchain via the Wasabi protocol. Microsoft warns that this architecture increases the resilience of DeadLock’s communication and negotiation infrastructure, posing new challenges for disruption.

Attack groups: DeadLock, Lynx, INC Ransomware

Malware: DeadLock Ransomware, Lynx Ransomware, INC Ransomware

Companies: Microsoft, Group-IB

Products: Session, AnyDesk, Polygon, Wasabi