Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors deadlock

Also known as: tracked as, Mustang Panda

Description

DeadLock’s operations are structured around a highly modular ransomware delivery package that starts with a lightweight CMD payload dropped into the victim’s ProgramData folder. The loader configures the console code‑page to UTF‑8, disables command‑line utilities, updates the DefaultIcon registry for its custom ".dlock" extension and replaces the desktop wallpaper with an image designed to appear as part of a legitimate note. After a 50‑second sandbox‑evading delay it recursively scans directories while applying exclusion filters and encrypts files using a custom time‑based stream cipher. The group demonstrates significant defensive evasion capabilities, including BYOVD driver injection (Baidu Antivirus CVE‑2024‑51324) to terminate EDR processes and stopping all native Windows services except AnyDesk for Remote Desktop Management. DeadLock also leverages Polygon smart contracts to rotate proxy IPs in real time, ensuring low‑visibility command‑and‑control communication even when network traffic is inspected. Operationally, the threat actor targets utility providers, defense contractors, financial firms and telecommunications companies—sectors with high potential for extortion payment. The campaign spans multiple regions (US, IQ, IR, CN, PK, TW) and employs a rapid, low‑noise approach: payloads self‑delete post‑execution, and ransom notes are left in each affected folder to prompt immediate action.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Utilities
Government
Financial services
Defense
Manufacturing
Telecommunications

Targeted Countries / Regions

US
IQ
IR
CN
PK
TW

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 16 hours ago

Executive Summary

DeadLock is a moderately sophisticated criminal ransomware group active in 2026‑08 that targets critical infrastructure and government entities across the US, Iran, Iraq, China, Pakistan, and Taiwan for financial gain. The actor employs a multi‑stage delivery chain leveraging command scripts, Remote Desktop software, and encrypted proxy rotations to evade detection while systematically destroying backups and hijacking system services. Victims receive customized ransom notes demanding Bitcoin or Monero, accompanied by visual cues such as altered icons and wallpaper.

Goals & Targeting

DeadLock’s primary strategic objective is monetary gain through ransomware extortion. By focusing on high‑value sectors such as utilities, defense and finance, the group maximizes pressure by threatening critical operations. The use of Remote Desktop software and proxy rotation allows for flexible lateral movement and a low attack surface, reflecting a calculated balance between reach and stealth.

Enhanced Description

Key Capabilities

  • Uses Polygon smart contracts to rotate proxy server addresses for stealth
  • Implements BYOVD technique by loading Baidu Antivirus driver CVE‑2024‑51324 in kernel mode to terminate EDR processes
  • Encrypts victim files with a custom time-based stream cipher
  • Assigns .dlock extensions and alters icons/wallpaper as ransom cues
  • Stops all native Windows services except AnyDesk
  • Destroys backups and shadow copies to inhibit system recovery
  • Deploys via CMD and PowerShell scripts that self‑delete after execution for evasion
  • Communicates with victims through a session messenger app or Remote Desktop software (AnyDesk) for RMM and ransom negotiation
  • Deploys a .cmd loader in ProgramData that sets console code page to UTF‑8 and launches the ransomware binary before self‑deleting
  • Recursively traverses directories while applying exclusion filters to enumerate files
  • Encrypts target files with a stream cipher after a 50-second delay to evade sandbox analysis
  • Drops an icon file and bitmap image, configures DefaultIcon registry key for .dlock extensions, changes desktop wallpaper
  • Disables command line utilities
  • Generates ransom note in each affected folder containing recovery process/payment options (Bitcoin or Monero) and warns against renaming third‑party decryption attempts
  • Persists victim identifier as a text file

MITRE ATT&CK Tactics

Execution
Defense Evasion
Impact

ATT&CK Techniques

T1033
T1548.002
T1489
T1559.002
T1069.002
T1566.001
T1559.001
T1675
T1053
T1106
T1218
T1610
T1112
T1674
T1059
T1677
T1609
T1559.003
T1102
T1059.001
T1559
T1574
T1078
T1486
T1203
T1197
T1219.002
T1070.004
T1651
T1018
T1046
T1648
T1021.001
T1569.002
T1490
T1211
T1218.014
T1562.001
T1562.004

Software / Tooling

DeadLock Ransomware
Raspberry Robin Malware
Hive0154

Campaigns & Victims

The DeadLock campaign emerged on May 22, 2026 and had active operations until at least August 10 of the same year. With over 76 confirmed victims across six countries, the group demonstrates a focused, rapidly deploying methodology that prioritizes key infrastructure sectors—utilities, defense, government, finance, manufacturing, and telecommunications. The actor’s use of remote shell control via AnyDesk alongside encrypted back‑channel communication suggests a blend of low‑profile movement and aggressive ransomware deployment.

IOC Patterns

  • Batch script (.cmd) dropped in ProgramData folder
  • Icon file and bitmap image placed in ProgramData
  • Registry modification of DefaultIcon key for .dlock extensions
  • Custom desktop wallpaper set by ransomware
  • Command line utilities disabled by malware
  • Ransom note containing Bitcoin/Monero addresses and victim ID

Recommended Actions

  • Implement endpoint monitoring for unexpected .cmd files created in ProgramData
  • Enforce whitelisting or blocking of arbitrary batch script execution on endpoints
  • Deploy detection and alerting for changes to DefaultIcon registry entries and custom desktop wallpaper
  • Track large‑scale file enumeration activities followed by encryption behavior
  • Block unauthorized changes to system services, especially those stopping native Windows services
  • Use kernel‑mode EDR solutions capable of detecting driver injection like Baidu Antivirus CVE‑2024‑51324 exploitation

Suggested Tags

ransomware
deadlock
windows
batch-script
icon-spoofing
wallpaper-change
bitcoin
monero
defense-evasion
registry-modification
proxy-rotation
byovd
service-stop

Confidence Assessment

The available data provide a cohesive view of DeadLock’s operational footprint and TTPs, drawing from multiple intelligence slices. Confidence is moderate due to the brief active window (May–August 2026) and reliance on publicly reported victims; additional evidence such as attribution markers or long‑term campaign evolution remains unavailable.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 4 SHA-1 Hash 4 Domain 6 Filename 3 SHA-256 Hash 2 URL 1

References

  1. attack.mitre.org — Cited by web research for: Mustang Panda
  2. www.group-ib.com — Cited by web research for: T1490
  3. blog.talosintelligence.com — Cited by web research for: T1211
  4. attack.mitre.org — Cited by web research for: T1197
  5. cloud.google.com — Cited by web research for: Ransomware payload
  6. https://capec.mitre.org/data/definitions/25.html — Cited by AI analysis.

Intel Summary

40

Techniques

45

Tools

630

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

ransomware
deadlock
windows
batch-script
icon-spoofing
wallpaper-change
bitcoin
monero
defense-evasion
registry-modification
proxy-rotation
byovd
service-stop

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
May 22, 2026
Last Seen
Aug 10, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.