Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Deadlock: ransomware that hides its C2 on the blockchain

Jesse William McGrawBy Jesse William McGrawJuly 18, 2026No Comments4 Mins Read1,229 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Deadlock: ransomware that hides its C2 on the blockchain, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Deadlock is the most technically novel ransomware group to surface in 2026. After roughly 11 months operating underground, it emerged publicly in June 2026, when researchers logged around 75 victims in a single month. Its signature is command-and-control built on Polygon smart contracts, a decentralized channel that is far harder to seize or sinkhole than ordinary servers, paired with kernel-level EDR termination through a vulnerable driver (CVE-2024-51324). Deadlock negotiates over the Session messenger. It is a preview of what takedown-resistant ransomware infrastructure looks like.

Who is Deadlock?

Deadlock is a ransomware operation that developed quietly for about 11 months before its public emergence in June 2026. It draws attention less for volume than for tradecraft: it engineered its infrastructure to survive the exact disruption tactics law enforcement has leaned on against groups like LockBit. Group-IB and other vendors flagged it as an emerging threat worth watching. For context on the wider field, see the Ransomnews threat-group catalogue and the live Ransomtracker feed.

Why smart-contract command-and-control matters

Traditional command-and-control relies on servers and domains that defenders and police can seize, block, or sinkhole. Deadlock instead reads its instructions from smart contracts on the Polygon blockchain. A blockchain has no single server to take down and no domain to revoke, and updates written to a contract propagate to every implant that queries it. To disrupt this channel, defenders would have to block the malware’s ability to reach the blockchain at all, a far harder proposition than pulling a hosting provider’s plug. It is decentralization repurposed as resilience for crime.

DEADLOCK // WHY BLOCKCHAIN C2 RESISTS TAKEDOWN TRADITIONAL C2 C2 server → SEIZED / SINKHOLED = implants go dark DEADLOCK: POLYGON SMART CONTRACT block block block No server to seize. No domain to revoke. TAKEDOWN-RESISTANTproxy rotation via contract ALSO: kernel EDR-kill via vulnerable driver (CVE-2024-51324) Emerged publicly June 2026 (~75 victims) after ~11 months underground. Negotiates via Session.

What else does Deadlock do?

Beyond its C2, Deadlock uses a vulnerable driver, tracked as CVE-2024-51324, to terminate endpoint detection at the kernel level before encrypting, the same bring-your-own-vulnerable-driver pattern seen across 2026’s top operations. Negotiations run over Session, an encrypted messenger with no phone-number requirement, keeping communications off channels that are easier to monitor. The combination, resilient C2, kernel EDR-kill, and anonymized negotiation, shows a group optimizing every stage against the standard disruption and detection playbook.

What Deadlock signals for 2026 and beyond

Deadlock is a proof of concept that ransomware infrastructure can be built to outlast takedowns. If smart-contract C2 proves reliable at scale, it undercuts one of law enforcement’s most effective tools: seizing and sinkholing infrastructure. Other groups will watch whether Deadlock’s approach holds up operationally. For defenders, the implication is that stopping the intrusion earlier matters more than ever, because disrupting the malware’s infrastructure after the fact gets harder when that infrastructure lives on a public blockchain.

How to defend against Deadlock

Focus on the entry and pre-encryption phases, where Deadlock is still stoppable. Enable Microsoft’s vulnerable-driver blocklist to blunt the CVE-2024-51324 EDR-kill step, and alert on a new kernel driver loading before security services fail. Monitor for unexpected outbound connections to blockchain nodes or RPC endpoints from servers that have no business talking to them, a possible sign of smart-contract C2. Keep offline, tested backups, and prioritize closing initial-access vectors, since post-infection infrastructure disruption is unusually difficult here.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Frequently asked questions

What is Deadlock ransomware?

Deadlock is a ransomware group that emerged publicly in June 2026 after about 11 months underground. It is known for command-and-control built on Polygon smart contracts and kernel-level EDR termination.

How does Deadlock’s blockchain C2 work?

Deadlock reads instructions from smart contracts on the Polygon blockchain instead of from seizable servers or domains, making its command-and-control channel highly resistant to takedown and sinkholing.

Why is smart-contract C2 hard to stop?

A blockchain has no central server to seize or domain to revoke, and instructions written to a contract reach every implant that queries it. Disrupting it requires blocking the malware’s access to the blockchain entirely.

Does Deadlock bypass EDR?

Yes. Deadlock uses a vulnerable driver tracked as CVE-2024-51324 to terminate endpoint detection at the kernel level before encrypting, a bring-your-own-vulnerable-driver technique.

How can defenders stop Deadlock?

Concentrate on initial access and the pre-encryption phase: block vulnerable drivers, alert on suspicious kernel-driver loads and unexpected blockchain-node connections, and keep offline backups, since disrupting its C2 after infection is very hard.

Sources and further reading

  • Group-IB: Deadlock ransomware and Polygon smart contracts
  • The Register: Deadlock ransomware uses smart contracts (January 14, 2026)
  • ReliaQuest: Ransomware and cyber extortion in Q2 2026 (July 16, 2026)
  • Ransomnews threat-group catalogue

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleClover Health discloses social-engineering breach in 8-K
Next Article wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Micro-Comm hack is separate from the US water attacks

September 1, 2026

Love Electric driver data for sale: NI, licence numbers

August 28, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.