Cybersecurity researchers are becoming interested in a newly discovered ransomware strain called DeadLock that abuses Polygon smart contracts to silently serviceCybersecurity researchers are becoming interested in a newly discovered ransomware strain called DeadLock that abuses Polygon smart contracts to silently service

Beware: New ‘DeadLock’ Ransomware Weaponizes Polygon Smart Contracts to Stay Invisible

Cybersecurity researchers are becoming interested in a newly discovered ransomware strain called DeadLock that abuses Polygon smart contracts to silently service its infrastructure and bypass conventional detection tools, as a recent report by threat intelligence firm Group-IB depicts.

DeadLock, first observed in July 2025, has so far remained largely under the radar because it does not have a publicly facing affiliate program, it does not have a data leak site, and its victims have been connected to comparatively few confirmed victims.

That profile, however, covers a more technologically sophisticated strategy that researchers believe is showing a more global change in the way cybercriminals are using public blockchains for criminal ends.

How DeadLock Hides Ransomware Infrastructure Inside Polygon Smart Contracts

Group-IB’s analysis shows that DeadLock uses smart contracts deployed on the Polygon network to store and rotate proxy server addresses.

These proxies act as intermediaries between infected systems and the ransomware operators, allowing command-and-control traffic to shift endpoints without relying on centralized infrastructure that can be seized or blocked.

By querying the smart contract, the malware retrieves the current proxy address through a simple read operation that leaves no obvious transactional footprint and incurs no network cost.

Researchers said this technique mirrors earlier campaigns, such as EtherHiding, disclosed last year, in which North Korean threat actors used the Ethereum blockchain to conceal and distribute malware payloads.

In both cases, public and decentralized ledgers were turned into resilient communication channels that are difficult for defenders to disrupt. DeadLock’s use of Polygon extends that concept by embedding proxy management directly into a smart contract, allowing attackers to update infrastructure on demand.

Source: Group-IB

Once deployed, DeadLock encrypts files and appends a “.dlock” extension, alters system icons, and replaces the victim’s wallpaper with ransom instructions.

Over time, the group’s ransom notes have evolved, with early samples referencing only file encryption, while later versions explicitly stated that sensitive data had been stolen and threatened its sale if payment was not made.

The most recent ransom notes also promise “added services,” including a breakdown of how the network was breached and assurances that the victim will not be targeted again.

This Ransomware Doesn’t Just Lock Files — It Opens a Chat With Hackers

Group-IB identified at least three distinct DeadLock samples from mid-2025, each showing incremental changes in tactics.

Analysis of associated PowerShell scripts suggests the malware aggressively disables non-essential services, deletes volume shadow copies to prevent recovery, and whitelists a limited set of processes, notably including AnyDesk

Investigators believe AnyDesk is used as the primary remote access tool during attacks, a finding consistent with separate digital forensics investigations.

A key element of DeadLock’s operation is an HTML file dropped on infected systems that embeds an encrypted session messenger interface. Victims can communicate directly with attackers through this file without installing additional software.

Source: Group-IB

The embedded JavaScript retrieves proxy addresses from the Polygon smart contract, then routes encrypted messages through those servers to a session ID controlled by the ransomware operators.

Transaction analysis shows that the same wallet created multiple identical smart contracts and repeatedly updated proxy addresses by calling a function labeled “setProxy.”

The wallet was funded through an exchange-linked address shortly before the contracts were deployed, indicating deliberate preparation.

Historical tracking of these transactions allows defenders to reconstruct past proxy infrastructure, although the decentralized design complicates rapid takedown efforts.

The finding is part of an overall increase in crypto-related cybercrime, as over $3.4 billion was stolen by hacks and exploits as of early December 2025, with state-linked North Korean groups accounting for over $2 billion of that total.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.004981
$0.004981$0.004981
-1.63%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Synthetix Launches Perpetual DEX with $1M Trading Competition

Synthetix Launches Perpetual DEX with $1M Trading Competition

The post Synthetix Launches Perpetual DEX with $1M Trading Competition appeared on BitcoinEthereumNews.com. Key Points: Synthetix launches Perp DEX with $1 million trading contest. Competition aims to stress-test new platform. Top traders are invited to participate with several rewards. Synthetix is set to launch its perpetual decentralized exchange (Perp DEX) on the Ethereum mainnet in Q4 2025, accompanied by a $1 million trading competition. The launch could boost Ethereum liquidity, attract top DeFi traders, and potentially increase the price volatility of involved tokens, including SNX and ETH. Synthetix Unveils $1M Trading Contest on Ethereum Mainnet The trading contest will attract top DeFi traders, with rewards funded by Synthetix’s treasury. Provisions for multi-collateral support will enhance the platform’s appeal, potentially increasing SNX token activity. Market response has been largely positive, particularly among developers and users on public platforms such as GitHub and Discord. Ethereum (ETH) is currently priced at $4,209.15 with a market cap of $508.06 billion. It holds 13.00% market dominance. CoinMarketCap data indicates a 0.21% price increase over 24 hours, despite a 10.54% drop in trading volume. “Synthetix is building the first high-performance perp to settle directly on Ethereum Mainnet, without the need for bridges or intermediaries. Synthetix mainnet features fast execution, low latency, and on-chain custody that leverages Ethereum’s robust security and liquidity.” – Kain Warwick, Founder, Synthetix Hybrid Model May Boost Institutional Interest in DeFi Did you know? Synthetix’s move to Ethereum Mainnet is a return to its roots, offering direct settlement without intermediaries, paralleling early on-chain derivatives attempts. The Coincu research team highlights that the hybrid model may foster institutional adoption by reducing gas costs. The competition could lead to increased SNX volatility and drive Ether-denominated TVL growth on the mainnet. Ethereum(ETH), daily chart, screenshot on CoinMarketCap at 08:35 UTC on September 23, 2025. Source: CoinMarketCap The competition could lead to increased SNX volatility and drive Ether-denominated TVL growth…
Share
BitcoinEthereumNews2025/09/23 16:45
Utah Man Receives 3-Year Sentence For $3M Deceptive Exchange Scheme

Utah Man Receives 3-Year Sentence For $3M Deceptive Exchange Scheme

The post Utah Man Receives 3-Year Sentence For $3M Deceptive Exchange Scheme appeared on BitcoinEthereumNews.com. Crypto Fraud Exposed: Utah Man Receives 3-Year
Share
BitcoinEthereumNews2026/01/16 11:56
Zero Knowledge Proof (ZKP) Set To Explode 3000x, Surpassing POL And Ethereum As The Next Crypto Breakout

Zero Knowledge Proof (ZKP) Set To Explode 3000x, Surpassing POL And Ethereum As The Next Crypto Breakout

Explore Zero Knowledge Proof (ZKP) as it targets 3000x gains, outperforming POL and Ethereum while capturing major attention from crypto investors worldwide.
Share
CoinLive2026/01/16 12:00