Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4

TLP:CLEAR
Active

SHA-256 Hash

Description

DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, t...

Sightings (0)

No sightings recorded yet

Details

Name / Label
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Pattern Type
STIX
Confidence
75%
Valid From
Aug 11, 2026 12:00
Total Sightings
0
Added
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.