Decoding the world of cybersecurity

DeadLock ransomware builds resilience around extortion

DeadLock has concentrated more than half of its claimed victims in Europe while using decentralised communications and leak infrastructure intended to make parts of its extortion operation harder to disrupt.

DeadLock ransomware builds resilience around extortion
Summary
  • Microsoft says more than half of the 80-plus organisations claimed by DeadLock as of July were in Europe.
  • The ransomware combines conventional double extortion with decentralised communications, blockchain-backed services, and distributed leak infrastructure.
  • The architecture reduces dependence on individual servers that law enforcement or hosting providers can remove, complicating disruption without making the operation untouchable.

More than half of the organisations claimed by the DeadLock ransomware operation are in Europe, while the group has built parts of its communications and extortion infrastructure around decentralised services designed to survive disruption.

Microsoft Threat Intelligence said DeadLock had published more than 80 organisations on its data leak site by July 2026, with European victims accounting for a majority of those claims. Microsoft has separately identified the ransomware affecting organisations across information technology, transport and logistics, manufacturing, mining, hospitality, consumer goods, and other sectors.

The distinction between claimed and confirmed victims remains important. Ransomware leak sites are coercive infrastructure and their contents cannot automatically be treated as evidence that every listed organisation was successfully compromised. Microsoft’s wider telemetry nevertheless establishes DeadLock as an active operation with a significant European footprint rather than a collection of unsupported criminal claims.

DeadLock has been observed since July 2025 and follows the familiar double-extortion model of encrypting systems while threatening to publish stolen information. Its more distinctive feature is the infrastructure surrounding that process. Microsoft found the operation using the Session messaging network alongside blockchain-backed services that store and deliver material used for victim communications, negotiations, and data-leak activity. The design reduces reliance on a conventional collection of web servers that can be seized, suspended, or removed from hosting providers.

That does not make the infrastructure immune to intervention. It changes where pressure can be applied. Traditional ransomware disruption has frequently targeted leak sites, negotiation portals, hosting accounts, domains, and servers used to coordinate attacks. Distributing parts of those functions across decentralised systems gives an operator alternative routes to recover or continue services when individual components disappear. The result is less a technically invulnerable ransomware platform than an extortion business designed to tolerate infrastructure loss.

The ransomware itself is written in Rust and includes measures intended to control the impact of encryption on the infected machine while the attack is in progress. Microsoft found resource-aware throttling designed to maintain system responsiveness and language-based geofencing that causes the malware to avoid systems associated with a number of former Soviet and Commonwealth of Independent States countries, as well as selected Middle Eastern states. Such exclusions are common across parts of the ransomware ecosystem but do not by themselves establish where the operators are based.

Microsoft has also observed DeadLock being deployed by more than one criminal group, including an affiliate associated with the Lynx and INC ransomware ecosystems. That complicates attempts to treat the ransomware name as a single, self-contained organisation. Modern ransomware operations often separate malware development, infrastructure, access, negotiation, and deployment between different participants, which means the same encryptor can appear in incidents with different operational fingerprints.

The concentration of claimed European victims gives the infrastructure design a more immediate significance for organisations in the region. Disruption of ransomware services has become an increasingly visible part of European and international law-enforcement strategy, alongside arrests, cryptocurrency seizures, server takedowns, and sanctions. Operators that can move negotiations and leak functions away from conventional hosting environments are adapting to that pressure rather than abandoning the extortion model.

DeadLock’s development also shows why ransomware resilience cannot be judged solely by whether a criminal leak site disappears. A takedown can impose cost and interrupt an operation without eliminating every channel through which an attacker can contact victims, recover infrastructure, or publish stolen material. For incident responders, insurers, law-enforcement agencies, and organisations facing extortion, the operational picture increasingly extends beyond the visible domain used to advertise victims.

Microsoft has published indicators and defensive guidance alongside its analysis. DeadLock remains an emerging operation rather than one of the most established ransomware brands, but its European victim concentration and infrastructure choices show how financially motivated groups are adapting their own resilience engineering to the disruption campaigns directed against them.

×