Microsoft Warns DeadLock Ransomware Can Keep Operating After Servers Go Down

Microsoft warns DeadLock ransomware can recover after server takedowns by using decentralized services to maintain victim communications and extortion.

Written By
LT
Liz Ticong
Aug 12, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A ransomware takedown can sever part of a criminal operation. DeadLock is designed to recover when some of that infrastructure disappears.

Microsoft Threat Intelligence says the ransomware uses decentralized services to keep victim communications available after individual servers are disrupted. Researchers began tracking the Rust-based malware in July 2025.

Company analysis identifies both the decentralized services supporting that recovery and the conventional infrastructure that remains exposed.

DeadLock spreads recovery across decentralized services

Microsoft’s DeadLock analysis details a recovery page left on infected systems. It retrieves the current chat proxy from a smart contract on Polygon instead of relying on one fixed address.

If defenders block or take down a proxy, operators can change the address stored on-chain. Existing recovery pages can then reconnect without being replaced.

Session provides an encrypted channel for victim communications, while stolen files can be stored through Wasabi and exposed through the recovery page.

Despite its decentralized design, the operation still depends on infrastructure that defenders can disrupt. Proxies can be blocked, access to Polygon can be restricted, and externally hosted files can be removed. Similar ransomware infrastructure disruptions can therefore target components that remain outside those decentralized services.

Familiar ransomware tactics remain central to DeadLock

By July 2026, the group had published more than 80 compromised organizations on its leak site. More than half were in Europe, with victims spanning sectors such as IT, manufacturing, logistics, hospitality, and mining.

Operators also use double extortion, stealing data before encryption and threatening to publish it if victims refuse their demands. Stolen information can continue giving attackers leverage after an organization starts restoring affected systems.

Researchers found the malware can stop security and backup services. Its encryption process can also slow when CPU or memory use rises, helping an infected machine remain responsive. Large files may be encrypted only in part to reduce the time needed to render them unusable.

Advertisement

Multiple groups have deployed DeadLock, according to Microsoft. One observed affiliate was previously associated with the Lynx and INC ransomware ecosystems.

Planning beyond a server takedown

Security teams should account for attacker infrastructure changing during an incident. A tested incident response plan should keep containment focused on the affected environment, where responders can verify compromised systems and accounts before recovery begins.

Response priorities include:

  • Preserve telemetry away from affected endpoints. DeadLock can clear Windows event logs and disable future logging, so endpoint and identity data should remain available in centralized systems attackers cannot easily alter.
  • Isolate affected systems promptly. Network segmentation can limit further access while responders determine which hosts and accounts have been compromised.
  • Protect security controls and recovery copies. Microsoft recommends EDR in block mode and tamper protection. Keep trusted backups beyond the attacker’s reach as part of broader ransomware protection measures.
  • Verify access is removed before restoration. Review compromised credentials and persistence mechanisms before reconnecting recovered systems to trusted parts of the network.

Loss of a DeadLock proxy or negotiation channel does not confirm attackers have been removed from the environment. Ransomware recovery should begin only after responders have verified containment and confirmed systems can be restored safely.

Also read: OpenAI’s GPT-5.6-Cyber targets advanced vulnerability research and exploit testing under tightly restricted access. 

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.