Also known as: tracked as, Mustang Panda
DeadLock’s operations are structured around a highly modular ransomware delivery package that starts with a lightweight CMD payload dropped into the victim’s ProgramData folder. The loader configures the console code‑page to UTF‑8, disables command‑line utilities, updates the DefaultIcon registry for its custom ".dlock" extension and replaces the desktop wallpaper with an image designed to appear as part of a legitimate note. After a 50‑second sandbox‑evading delay it recursively scans directories while applying exclusion filters and encrypts files using a custom time‑based stream cipher. The group demonstrates significant defensive evasion capabilities, including BYOVD driver injection (Baidu Antivirus CVE‑2024‑51324) to terminate EDR processes and stopping all native Windows services except AnyDesk for Remote Desktop Management. DeadLock also leverages Polygon smart contracts to rotate proxy IPs in real time, ensuring low‑visibility command‑and‑control communication even when network traffic is inspected. Operationally, the threat actor targets utility providers, defense contractors, financial firms and telecommunications companies—sectors with high potential for extortion payment. The campaign spans multiple regions (US, IQ, IR, CN, PK, TW) and employs a rapid, low‑noise approach: payloads self‑delete post‑execution, and ransom notes are left in each affected folder to prompt immediate action.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DeadLock is a moderately sophisticated criminal ransomware group active in 2026‑08 that targets critical infrastructure and government entities across the US, Iran, Iraq, China, Pakistan, and Taiwan for financial gain. The actor employs a multi‑stage delivery chain leveraging command scripts, Remote Desktop software, and encrypted proxy rotations to evade detection while systematically destroying backups and hijacking system services. Victims receive customized ransom notes demanding Bitcoin or Monero, accompanied by visual cues such as altered icons and wallpaper.
Goals & Targeting
DeadLock’s primary strategic objective is monetary gain through ransomware extortion. By focusing on high‑value sectors such as utilities, defense and finance, the group maximizes pressure by threatening critical operations. The use of Remote Desktop software and proxy rotation allows for flexible lateral movement and a low attack surface, reflecting a calculated balance between reach and stealth.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The DeadLock campaign emerged on May 22, 2026 and had active operations until at least August 10 of the same year. With over 76 confirmed victims across six countries, the group demonstrates a focused, rapidly deploying methodology that prioritizes key infrastructure sectors—utilities, defense, government, finance, manufacturing, and telecommunications. The actor’s use of remote shell control via AnyDesk alongside encrypted back‑channel communication suggests a blend of low‑profile movement and aggressive ransomware deployment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provide a cohesive view of DeadLock’s operational footprint and TTPs, drawing from multiple intelligence slices. Confidence is moderate due to the brief active window (May–August 2026) and reliance on publicly reported victims; additional evidence such as attribution markers or long‑term campaign evolution remains unavailable.
No observed data linked yet.
40
Techniques
45
Tools
630
Campaigns
40
IOCs
0
Observed Data
10
Tactics