Microsoft details DeadLock extortion tactics
The use of blockchain and decentralized messaging makes the attacker's infrastructure more resilient to takedown efforts by authorities. This increases the difficulty of disrupting recovery and negotiation processes for infected organizations.
- First observed in July 2025 using double extortion tactics.
- Uses Polygon smart contracts for proxy configuration and data leak blog storage.
- Routes encrypted victim communication through the Session decentralized messenger network.
- Implements resource-aware throttling (29% RAM, 70% CPU thresholds) and hybrid Curve25519/XChaCha20 encryption.