Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

dlock.liveblog365.com

TLP:CLEAR
Active

Domain

Description

DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, t...

Sightings (0)

No sightings recorded yet

Details

Name / Label
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Pattern Type
STIX
Confidence
75%
Valid From
Aug 11, 2026 12:00
Total Sightings
0
Added
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of dlock.liveblog365.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.