SUBJECT PROFILE
DeadLock emerged in July 2025 operating quietly without a data leak site before detonating onto the ransomware leaderboard in June 2026 with 75–81 claimed victims, jumping to second place globally. The group is technically distinguished by its use of Polygon blockchain smart contracts for C2 proxy address rotation (EtherHiding technique), and by kernel-level EDR termination via a BYOVD attack exploiting the vulnerable Baidu Antivirus driver (CVE-2024-51324). Its sudden leap in victim volume in June 2026 after 11 months of relative silence suggests a deliberate backlog-release strategy or rapid affiliate expansion.
Financial extortion; opportunistic targeting across global sectors
OPERATIONAL HISTORY
Polygon smart contract-based C2 proxy rotation (EtherHiding), BYOVD EDR termination via vulnerable Baidu driver (BdApiUtil.sys, CVE-2024-51324), Windows shadow copy deletion, PowerShell-based service termination prior to encryption, Session messaging app for victim negotiation (no public DLS initially), double extortion with data theft threats
KNOWN INFRASTRUCTURE
C++ ransomware binary targeting Windows systems; Polygon (MATIC) blockchain smart contracts for C2 proxy storage/rotation; Session end-to-end encrypted messaging for victim communications; newly activated clearnet DLS (deadlock.liveblog365[.]com — observed June 16, 2026); no known affiliate program initially (possible shift in mid-2026)