Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Deadlock: ransomware that hides its C2 on the blockchain

Jesse William McGrawBy Jesse William McGrawJuly 18, 2026No Comments4 Mins Read195 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Deadlock: ransomware that hides its C2 on the blockchain, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Deadlock is the most technically novel ransomware group to surface in 2026. After roughly 11 months operating underground, it emerged publicly in June 2026, when researchers logged around 75 victims in a single month. Its signature is command-and-control built on Polygon smart contracts, a decentralized channel that is far harder to seize or sinkhole than ordinary servers, paired with kernel-level EDR termination through a vulnerable driver (CVE-2024-51324). Deadlock negotiates over the Session messenger. It is a preview of what takedown-resistant ransomware infrastructure looks like.

Who is Deadlock?

Deadlock is a ransomware operation that developed quietly for about 11 months before its public emergence in June 2026. It draws attention less for volume than for tradecraft: it engineered its infrastructure to survive the exact disruption tactics law enforcement has leaned on against groups like LockBit. Group-IB and other vendors flagged it as an emerging threat worth watching. For context on the wider field, see the Ransomnews threat-group catalogue and the live Ransomtracker feed.

Why smart-contract command-and-control matters

Traditional command-and-control relies on servers and domains that defenders and police can seize, block, or sinkhole. Deadlock instead reads its instructions from smart contracts on the Polygon blockchain. A blockchain has no single server to take down and no domain to revoke, and updates written to a contract propagate to every implant that queries it. To disrupt this channel, defenders would have to block the malware’s ability to reach the blockchain at all, a far harder proposition than pulling a hosting provider’s plug. It is decentralization repurposed as resilience for crime.

DEADLOCK // WHY BLOCKCHAIN C2 RESISTS TAKEDOWN TRADITIONAL C2 C2 server → SEIZED / SINKHOLED = implants go dark DEADLOCK: POLYGON SMART CONTRACT block block block No server to seize. No domain to revoke. TAKEDOWN-RESISTANTproxy rotation via contract ALSO: kernel EDR-kill via vulnerable driver (CVE-2024-51324) Emerged publicly June 2026 (~75 victims) after ~11 months underground. Negotiates via Session.

What else does Deadlock do?

Beyond its C2, Deadlock uses a vulnerable driver, tracked as CVE-2024-51324, to terminate endpoint detection at the kernel level before encrypting, the same bring-your-own-vulnerable-driver pattern seen across 2026’s top operations. Negotiations run over Session, an encrypted messenger with no phone-number requirement, keeping communications off channels that are easier to monitor. The combination, resilient C2, kernel EDR-kill, and anonymized negotiation, shows a group optimizing every stage against the standard disruption and detection playbook.

What Deadlock signals for 2026 and beyond

Deadlock is a proof of concept that ransomware infrastructure can be built to outlast takedowns. If smart-contract C2 proves reliable at scale, it undercuts one of law enforcement’s most effective tools: seizing and sinkholing infrastructure. Other groups will watch whether Deadlock’s approach holds up operationally. For defenders, the implication is that stopping the intrusion earlier matters more than ever, because disrupting the malware’s infrastructure after the fact gets harder when that infrastructure lives on a public blockchain.

How to defend against Deadlock

Focus on the entry and pre-encryption phases, where Deadlock is still stoppable. Enable Microsoft’s vulnerable-driver blocklist to blunt the CVE-2024-51324 EDR-kill step, and alert on a new kernel driver loading before security services fail. Monitor for unexpected outbound connections to blockchain nodes or RPC endpoints from servers that have no business talking to them, a possible sign of smart-contract C2. Keep offline, tested backups, and prioritize closing initial-access vectors, since post-infection infrastructure disruption is unusually difficult here.

Frequently asked questions

What is Deadlock ransomware?

Deadlock is a ransomware group that emerged publicly in June 2026 after about 11 months underground. It is known for command-and-control built on Polygon smart contracts and kernel-level EDR termination.

How does Deadlock’s blockchain C2 work?

Deadlock reads instructions from smart contracts on the Polygon blockchain instead of from seizable servers or domains, making its command-and-control channel highly resistant to takedown and sinkholing.

Why is smart-contract C2 hard to stop?

A blockchain has no central server to seize or domain to revoke, and instructions written to a contract reach every implant that queries it. Disrupting it requires blocking the malware’s access to the blockchain entirely.

Does Deadlock bypass EDR?

Yes. Deadlock uses a vulnerable driver tracked as CVE-2024-51324 to terminate endpoint detection at the kernel level before encrypting, a bring-your-own-vulnerable-driver technique.

How can defenders stop Deadlock?

Concentrate on initial access and the pre-encryption phase: block vulnerable drivers, alert on suspicious kernel-driver loads and unexpected blockchain-node connections, and keep offline backups, since disrupting its C2 after infection is very hard.

Sources and further reading

  • Group-IB: Deadlock ransomware and Polygon smart contracts
  • The Register: Deadlock ransomware uses smart contracts (January 14, 2026)
  • ReliaQuest: Ransomware and cyber extortion in Q2 2026 (July 16, 2026)
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleClover Health discloses social-engineering breach in 8-K
Next Article wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.