A ransomware takedown can sever part of a criminal operation. DeadLock is designed to recover when some of that infrastructure disappears.
Microsoft Threat Intelligence says the ransomware uses decentralized services to keep victim communications available after individual servers are disrupted. Researchers began tracking the Rust-based malware in July 2025.
Company analysis identifies both the decentralized services supporting that recovery and the conventional infrastructure that remains exposed.
DeadLock spreads recovery across decentralized services
Microsoft’s DeadLock analysis details a recovery page left on infected systems. It retrieves the current chat proxy from a smart contract on Polygon instead of relying on one fixed address.
If defenders block or take down a proxy, operators can change the address stored on-chain. Existing recovery pages can then reconnect without being replaced.
Session provides an encrypted channel for victim communications, while stolen files can be stored through Wasabi and exposed through the recovery page.
Despite its decentralized design, the operation still depends on infrastructure that defenders can disrupt. Proxies can be blocked, access to Polygon can be restricted, and externally hosted files can be removed. Similar ransomware infrastructure disruptions can therefore target components that remain outside those decentralized services.
Familiar ransomware tactics remain central to DeadLock
By July 2026, the group had published more than 80 compromised organizations on its leak site. More than half were in Europe, with victims spanning sectors such as IT, manufacturing, logistics, hospitality, and mining.
Operators also use double extortion, stealing data before encryption and threatening to publish it if victims refuse their demands. Stolen information can continue giving attackers leverage after an organization starts restoring affected systems.
Researchers found the malware can stop security and backup services. Its encryption process can also slow when CPU or memory use rises, helping an infected machine remain responsive. Large files may be encrypted only in part to reduce the time needed to render them unusable.
Multiple groups have deployed DeadLock, according to Microsoft. One observed affiliate was previously associated with the Lynx and INC ransomware ecosystems.
Planning beyond a server takedown
Security teams should account for attacker infrastructure changing during an incident. A tested incident response plan should keep containment focused on the affected environment, where responders can verify compromised systems and accounts before recovery begins.
Response priorities include:
- Preserve telemetry away from affected endpoints. DeadLock can clear Windows event logs and disable future logging, so endpoint and identity data should remain available in centralized systems attackers cannot easily alter.
- Isolate affected systems promptly. Network segmentation can limit further access while responders determine which hosts and accounts have been compromised.
- Protect security controls and recovery copies. Microsoft recommends EDR in block mode and tamper protection. Keep trusted backups beyond the attacker’s reach as part of broader ransomware protection measures.
- Verify access is removed before restoration. Review compromised credentials and persistence mechanisms before reconnecting recovered systems to trusted parts of the network.
Loss of a DeadLock proxy or negotiation channel does not confirm attackers have been removed from the environment. Ransomware recovery should begin only after responders have verified containment and confirmed systems can be restored safely.
Also read: OpenAI’s GPT-5.6-Cyber targets advanced vulnerability research and exploit testing under tightly restricted access.





