As cited
Copy frozen at (site build).
ransomware
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is a Rust-based ransomware first observed in July 2025 that uses decentralized infrastructure, including blockchain-based smart contracts and the Session messaging network, to manage victim communications and host exfiltrated data. The encryptor employs a hybrid cryptographic scheme combining Curve25519 and XChaCha20, implements resource-aware throttling to maintain system responsiveness during encryption, and includes geofencing to avoid Commonwealth of Independent States and select Middle Eastern countries. As of July 2026, operators have published more than 80 compromised organizations across multiple sectors and continents, using double extortion tactics and a novel recovery chat system embedded in an HTML file.
Why it matters: Organizations in IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors worldwide need immediate visibility into DeadLock's technical capabilities, indicators of compromise, and defensive measures including controlled folder access policies, EDR in block mode, and attack surface reduction rules to prevent encryption and data exfiltration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Researchers describe DeadLock as a Rust-based ransomware that employs decentralized communication channels for victim negotiation. The malware incorporates language-based geofencing to avoid execution in certain regions and uses a throttling mechanism to limit system impact during encryption. Microsoft tracks the threat across multiple industries and provides indicators of compromise and detection guidance.
Why it matters: Organizations running Windows environments face file encryption and data exposure from DeadLock ransomware, requiring verification of backup integrity and review of endpoint detection controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Researchers describe DeadLock as a Rust-based ransomware that employs decentralized communication channels for victim negotiation. The malware incorporates language-based geofencing to avoid execution in certain regions and uses a throttling mechanism to limit system impact during encryption. Microsoft tracks the threat across multiple industries and provides indicators of compromise and detection guidance.
Why it matters: Organizations running Windows environments face file encryption and data exposure from DeadLock ransomware, requiring verification of backup integrity and review of endpoint detection controls.
- Source published
- First seen by Cybersecurity Tracker