Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

deadlock Ransomware Group

Ransomware group profile

114Victims
RussiaSource country
80Impact score

Description

DeadLock is a financially motivated ransomware group that emerged in mid-July 2025. The group employs double extortion tactics, demanding ransom payments in cryptocurrencies while threatening to sell stolen data on underground markets. They utilize innovative techniques, such as blockchain smart contracts, to manage their command-and-control infrastructure, enhancing their evasion capabilities.

Key insights

  • •Utilizes innovative Polygon blockchain smart contracts to manage C2 proxy server addresses.
  • •Employs double extortion tactics, threatening to sell exfiltrated data instead of maintaining a public leak site.
  • •Initial access typically involves exploiting vulnerabilities like CVE-2024-51324 in Baidu Antivirus.
  • •Ransomware is written in C++ and uses a custom stream cipher with time-based cryptographic keys.
  • •Targets multiple sectors including Real Estate, Health Care, and Manufacturing.
  • •Engages in defense evasion techniques such as process hollowing and PowerShell script executions.
  • •Communication with victims is facilitated through Session messenger using an HTML-based interface.

Threat Level & Status Breakdown

For deadlock · Based on incidents in selected period

2.6threat level
Aggressiveness6/ 10
Lethality0.3/ 10
Criticality1.3/ 10

Status Breakdown

Data Leaked5.3%6
Claimed94.7%108
First seenMay 2026
Last seenOct 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedOct 8, 2026

Recent activity

Monthly attack count for deadlock in the selected period

114Total attacks
71peak in Jul
22.8avg / month
↓ 6 vs first month
MayJunJulAugOct020406080

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for deadlock

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Other

T1311

T1311

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(113)

ItalyOthergreggio.com
Claimed
3 days ago
Claimed
7 days ago
GreeceOtherrogdianakis.gr
Claimed
7 days ago
United StatesManufacturingfarwestcontractors.com
Claimed
7 days ago
United StatesProfessional Servicesslgjustice.com
Data Leaked
about 2 months ago
South AfricaOtherfurnbed.co.za
Claimed
about 2 months ago
United KingdomOthermolyneuxstudio.com
Claimed
about 2 months ago
TaiwanTechnologyufoc.com.tw
Claimed
about 2 months ago
TurkeyTransportationglobalterminal-tr.com
Claimed
about 2 months ago
PhilippinesManufacturingltg.com.ph
Data Leaked
about 2 months ago
LebanonHealthcarekamph.co
Claimed
about 2 months ago
TurkeyTechnologyahenklab.com.tr
Claimed
2 months ago
SpainManufacturingdiater.com
Claimed
2 months ago
ItalyTechnologypasello.com
Claimed
2 months ago
ItalyManufacturingtakisbiotech.com
Claimed
2 months ago
ChileTechnologyhasltda.com
Claimed
2 months ago
United KingdomRetail & E-Commercetesco-engineers.com
Claimed
2 months ago
United StatesTransportationhighclasscarlimo.com
Claimed
2 months ago
AustraliaEnergy & Utilitieswestafricanresources.com
Claimed
2 months ago
AzerbaijanEnergy & Utilitiescaspianone.com
Claimed
2 months ago

Page 1 of 6