Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

deadlock Ransomware Group

Ransomware group profile

110Victims
RussiaSource country
80Impact score

Description

DeadLock is a financially motivated ransomware group that emerged in mid-July 2025. The group employs double extortion tactics, demanding ransom payments in cryptocurrencies while threatening to sell stolen data on underground markets. They utilize innovative techniques, such as blockchain smart contracts, to manage their command-and-control infrastructure, enhancing their evasion capabilities.

Key insights

  • Utilizes innovative Polygon blockchain smart contracts to manage C2 proxy server addresses.
  • Employs double extortion tactics, threatening to sell exfiltrated data instead of maintaining a public leak site.
  • Initial access typically involves exploiting vulnerabilities like CVE-2024-51324 in Baidu Antivirus.
  • Ransomware is written in C++ and uses a custom stream cipher with time-based cryptographic keys.
  • Targets multiple sectors including Real Estate, Health Care, and Manufacturing.
  • Engages in defense evasion techniques such as process hollowing and PowerShell script executions.
  • Communication with victims is facilitated through Session messenger using an HTML-based interface.

Threat Level & Status Breakdown

For deadlock · Based on incidents in selected period

2.3threat level
Aggressiveness5/ 10
Lethality0.3/ 10
Criticality1.3/ 10

Status Breakdown

Data Leaked5.5%6
Claimed94.5%104
First seenMay 2026
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 17, 2026

Recent activity

Monthly attack count for deadlock in the selected period

110Total attacks
71peak in Jul
27.5avg / month
↓ 3 vs first month
MayJunJulAug020406080

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for deadlock

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Other

T1311

T1311

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(109)

United StatesProfessional Servicesslgjustice.com
Data Leaked
25 days ago
South AfricaOtherfurnbed.co.za
Claimed
25 days ago
United KingdomOthermolyneuxstudio.com
Claimed
29 days ago
TaiwanTechnologyufoc.com.tw
Claimed
30 days ago
TurkeyTransportationglobalterminal-tr.com
Claimed
30 days ago
PhilippinesManufacturingltg.com.ph
Data Leaked
about 1 month ago
LebanonHealthcarekamph.co
Claimed
29 days ago
TurkeyTechnologyahenklab.com.tr
Claimed
about 2 months ago
SpainManufacturingdiater.com
Claimed
about 2 months ago
ItalyTechnologypasello.com
Claimed
about 2 months ago
ItalyManufacturingtakisbiotech.com
Claimed
about 2 months ago
ChileTechnologyhasltda.com
Claimed
about 2 months ago
United KingdomRetail & E-Commercetesco-engineers.com
Claimed
about 2 months ago
United StatesTransportationhighclasscarlimo.com
Claimed
about 2 months ago
AustraliaEnergy & Utilitieswestafricanresources.com
Claimed
about 2 months ago
AzerbaijanEnergy & Utilitiescaspianone.com
Claimed
about 2 months ago
TurkeyManufacturinghidromek.com
Claimed
3 months ago
KenyaGovernment & Defense
Claimed
about 2 months ago
SwitzerlandProfessional Services
Claimed
about 2 months ago
PolandHealthcare
Claimed
about 2 months ago

Page 1 of 6