THE DeadLock ransomware is recognized as a severe double extortion threat, employing a blend of modern file encryption and decentralized blockchain technologies. Microsoft Threat Intelligence reports that this malware has targeted over 80 organizations worldwide across various sectors, including IT and manufacturing, often using criminal affiliates for distribution.
The ransomware initiates by decrypting configurations and checking system language settings, then elevates privileges, terminating security processes and erasing event logs to evade detection. Its unique communication infrastructure utilizes a decentralized messaging system and blockchain for recovery chats, increasing resilience against disruptions. To combat DeadLock, organizations should implement layered defenses, monitor for suspicious activity, and maintain secure backups.