← Blog · · df00tech

DeadLock Ransomware Adopts Blockchain-Backed Infrastructure to Evade Takedowns

security-news campaign

According to BleepingComputer, the DeadLock ransomware operation has been observed using decentralized, blockchain-backed services to protect its victim communication channels and data-leak site infrastructure from takedown efforts.

What Was Reported

Per the report, DeadLock is relying on blockchain-based decentralized infrastructure rather than traditional centralized hosting for the systems it uses to communicate with victims and publish stolen data. The underlying goal, as described, is resilience: infrastructure anchored to blockchain services is far harder for law enforcement and hosting providers to seize or take offline compared to conventional servers or Tor-hidden services alone. Beyond this infrastructure detail, specifics of DeadLock's initial access, encryption behavior, and victimology were not detailed in the source material.

Why It Matters for Defenders

Ransomware groups have historically been vulnerable to infrastructure disruption — leak sites and negotiation portals seized or sinkholed by law enforcement have repeatedly disrupted operations (e.g., LockBit, Hive). A shift toward blockchain-backed, decentralized infrastructure signals that ransomware operators are adapting specifically to counter this pressure point. If this approach proves effective, other ransomware-as-a-service groups may adopt similar architectures, making future takedown and disruption operations against leak sites and victim communication channels significantly harder to execute.

What Defenders Should Watch For

  • Treat any DeadLock-branded ransom note or negotiation portal link as potentially resolving to non-traditional, decentralized infrastructure rather than a standard clearnet or Tor .onion address — factor this into incident response and threat intel enrichment workflows.
  • Monitor outbound network traffic from endpoints for connections to blockchain-node RPC endpoints, IPFS gateways, or similar decentralized-web protocols in contexts where such traffic is unusual for the environment, as this can be a weak signal of C2 or exfiltration-adjacent activity tied to this style of infrastructure.
  • Ensure standard ransomware readiness controls remain in place regardless of infrastructure resilience on the attacker side: offline/immutable backups, EDR coverage, and restricted lateral movement paths — takedown-resistant leak infrastructure does not change the initial access or encryption phases of an attack.
  • Track threat intel feeds and law enforcement advisories for updated DeadLock indicators, as decentralized infrastructure will likely require different tracking and disruption approaches than past ransomware operations.

This is developing intelligence based on a single report, and no CVE or specific technical indicators have been published yet. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.