Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

deadlock Ransomware Group

Ransomware group profile

10Victims
RussiaSource country
80Impact score

Description

DeadLock is a financially motivated ransomware group that emerged in mid-July 2025. The group employs double extortion tactics, demanding ransom payments in cryptocurrencies while threatening to sell stolen data on underground markets. They utilize innovative techniques, such as blockchain smart contracts, to manage their command-and-control infrastructure, enhancing their evasion capabilities.

Key insights

  • Utilizes innovative Polygon blockchain smart contracts to manage C2 proxy server addresses.
  • Employs double extortion tactics, threatening to sell exfiltrated data instead of maintaining a public leak site.
  • Initial access typically involves exploiting vulnerabilities like CVE-2024-51324 in Baidu Antivirus.
  • Ransomware is written in C++ and uses a custom stream cipher with time-based cryptographic keys.
  • Targets multiple sectors including Real Estate, Health Care, and Manufacturing.
  • Engages in defense evasion techniques such as process hollowing and PowerShell script executions.
  • Communication with victims is facilitated through Session messenger using an HTML-based interface.

Threat Level & Status Breakdown

For deadlock · Based on incidents in selected period

3threat level
Aggressiveness7/ 10
Lethality0.3/ 10
Criticality1.3/ 10

Status Breakdown

Data Leaked6.0%6
Claimed94.0%94
First seenJul 2026
Last seenJul 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 27, 2026

Recent activity

Monthly attack count for deadlock in the selected period

10Total attacks
10peak in Jul
10avg / month
Jul036912

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for deadlock

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Other

T1311

T1311

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(109)

United StatesProfessional Servicesslgjustice.com
Data Leaked
4 days ago
South AfricaOtherfurnbed.co.za
Claimed
4 days ago
United KingdomOthermolyneuxstudio.com
Claimed
8 days ago
TaiwanTechnologyufoc.com.tw
Claimed
9 days ago
TurkeyTransportationglobalterminal-tr.com
Claimed
9 days ago
PhilippinesManufacturingltg.com.ph
Data Leaked
18 days ago
LebanonHealthcarekamph.co
Claimed
8 days ago
TurkeyTechnologyahenklab.com.tr
Claimed
about 1 month ago
SpainManufacturingdiater.com
Claimed
about 1 month ago
ItalyTechnologypasello.com
Claimed
about 1 month ago
ItalyManufacturingtakisbiotech.com
Claimed
about 1 month ago
ChileTechnologyhasltda.com
Claimed
about 1 month ago
United KingdomRetail & E-Commercetesco-engineers.com
Claimed
about 1 month ago
United StatesTransportationhighclasscarlimo.com
Claimed
about 1 month ago
AustraliaEnergy & Utilitieswestafricanresources.com
Claimed
about 1 month ago
AzerbaijanEnergy & Utilitiescaspianone.com
Claimed
about 1 month ago
TurkeyManufacturinghidromek.com
Claimed
2 months ago
KenyaGovernment & Defense
Claimed
about 1 month ago
SwitzerlandProfessional Services
Claimed
about 1 month ago
PolandHealthcare
Claimed
about 1 month ago

Page 1 of 6