DeadLock Ransomware Gang Uses Blockchain Tech to Dodge Takedowns
A ransomware group known as DeadLock is using decentralized technology to strengthen its extortion operations and make them more resistant to disruption by law enforcement and security researchers. According to Microsoft's Threat Intelligence team, the group combines the Session encrypted messaging network with blockchain-backed services—built on the Polygon network—to store and deliver key resources used throughout its attacks.
By relying on decentralized infrastructure rather than traditional servers, DeadLock reduces the risk that authorities can seize or take down the systems it uses to communicate with victims and host stolen data. This mirrors a broader trend among cybercriminal groups seeking infrastructure that is harder to trace and dismantle, as blockchain-based services are distributed across many nodes rather than concentrated in one location that can be targeted.
While the technical details of DeadLock's attack methods are still emerging, the use of decentralized and blockchain technology signals an evolution in ransomware tactics. Businesses should be aware that even if a ransomware group's communication or leak sites are reported and targeted, groups using this kind of infrastructure may prove more resilient and continue operating.