Ransomware Intelligence

deadlock

Ransomware group profile

75Victims
80Impact score

Description

DeadLock is a financially motivated ransomware group that emerged in mid-July 2025. The group employs double extortion tactics, demanding ransom payments in cryptocurrencies while threatening to sell stolen data on underground markets. They utilize innovative techniques, such as blockchain smart contracts, to manage their command-and-control infrastructure, enhancing their evasion capabilities.

Key insights

  • Utilizes innovative Polygon blockchain smart contracts to manage C2 proxy server addresses.
  • Employs double extortion tactics, threatening to sell exfiltrated data instead of maintaining a public leak site.
  • Initial access typically involves exploiting vulnerabilities like CVE-2024-51324 in Baidu Antivirus.
  • Ransomware is written in C++ and uses a custom stream cipher with time-based cryptographic keys.
  • Targets multiple sectors including Real Estate, Health Care, and Manufacturing.
  • Engages in defense evasion techniques such as process hollowing and PowerShell script executions.
  • Communication with victims is facilitated through Session messenger using an HTML-based interface.

Threat Level & Status Breakdown

For deadlock · Based on incidents in selected period

3.9threat level
Aggressiveness10/ 10
Lethality0.3/ 10
Criticality1.2/ 10

Status Breakdown

Data Leaked5.3%4
Claimed25.3%19
First seenMay 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for deadlock in the selected period

75Total attacks
65peak in Jun
37.5avg / month
↑ 55 vs first month
MayJun020406080

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for deadlock

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Other

T1311

T1311

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(75)

CompanyDomainCountryIndustryStatusDiscovered
Notice
Data Leaked
3 days ago
iASKHU HungaryEducation
Unknown
4 days ago
Noega and EsnovaES SpainManufacturing
Unknown
4 days ago
IFC EurES SpainManufacturing
Unknown
4 days ago
TPToysGB United KingdomManufacturing
Unknown
4 days ago
EXPRESOKNA SP. Z O.O.PL PolandManufacturing
Unknown
4 days ago
Bär Cargolift Polska Sp. z o.o.PL PolandManufacturing
Unknown
4 days ago
Grupolider | Grupo ActualAO AngolaOther
Data Leaked
4 days ago
Dyhrberg AG SwitzerlandCH SwitzerlandOther
Unknown
4 days ago
SKK Networks Sp. z o.o. and UNICARD Systems Sp. z o. o. and SKK SAPL PolandTechnology
Unknown
4 days ago
PB Sprinkler Engineering Sp. z o.o. and PLISZKA Fire Protection EngineeringPL PolandManufacturing
Unknown
4 days ago
8.2 Group e.V.DE GermanyEnergy & Utilities
Unknown
4 days ago
Integra and Operosa
Data Leaked
4 days ago
JOSONO NorwayManufacturing
Unknown
4 days ago
GEOPARTNER Sp. z o.o. and GEOPARTNER GEOMATICS Sp. z o.o.PL PolandProfessional Services
Unknown
4 days ago
FIRESTACZ Czech RepublicOther
Unknown
4 days ago
UFLPG Papua New GuineaFinancial Services
Unknown
4 days ago
PicassentES SpainGovernment & Defense
Unknown
4 days ago
StarconnTW TaiwanManufacturing
Unknown
4 days ago
EFCAFR FranceOther
Unknown
4 days ago

Page 1 of 4