CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Permanent story citation

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4176

As cited

Copy frozen at (site build).

ransomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock is a Rust-based ransomware first observed in July 2025 that uses decentralized infrastructure, including blockchain-based smart contracts and the Session messaging network, to manage victim communications and host exfiltrated data. The encryptor employs a hybrid cryptographic scheme combining Curve25519 and XChaCha20, implements resource-aware throttling to maintain system responsiveness during encryption, and includes geofencing to avoid Commonwealth of Independent States and select Middle Eastern countries. As of July 2026, operators have published more than 80 compromised organizations across multiple sectors and continents, using double extortion tactics and a novel recovery chat system embedded in an HTML file.

Why it matters: Organizations in IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors worldwide need immediate visibility into DeadLock's technical capabilities, indicators of compromise, and defensive measures including controlled folder access policies, EDR in block mode, and attack surface reduction rules to prevent encryption and data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Researchers describe DeadLock as a Rust-based ransomware that employs decentralized communication channels for victim negotiation. The malware incorporates language-based geofencing to avoid execution in certain regions and uses a throttling mechanism to limit system impact during encryption. Microsoft tracks the threat across multiple industries and provides indicators of compromise and detection guidance.

Why it matters: Organizations running Windows environments face file encryption and data exposure from DeadLock ransomware, requiring verification of backup integrity and review of endpoint detection controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Researchers describe DeadLock as a Rust-based ransomware that employs decentralized communication channels for victim negotiation. The malware incorporates language-based geofencing to avoid execution in certain regions and uses a throttling mechanism to limit system impact during encryption. Microsoft tracks the threat across multiple industries and provides indicators of compromise and detection guidance.

Why it matters: Organizations running Windows environments face file encryption and data exposure from DeadLock ransomware, requiring verification of backup integrity and review of endpoint detection controls.

VendorsMicrosoftAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary