DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // DEADLOCK-RAASFIRST SEEN: JUL 2025

DeadLock

ALSO KNOWN AS: Deadlock Ransomware
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUL 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL68/100
RESOURCES68/100
PERSISTENCE71/100
STEALTH63/100
IMPACT77/100

DeadLock emerged in July 2025 operating quietly without a data leak site before detonating onto the ransomware leaderboard in June 2026 with 75–81 claimed victims, jumping to second place globally. The group is technically distinguished by its use of Polygon blockchain smart contracts for C2 proxy address rotation (EtherHiding technique), and by kernel-level EDR termination via a BYOVD attack exploiting the vulnerable Baidu Antivirus driver (CVE-2024-51324). Its sudden leap in victim volume in June 2026 after 11 months of relative silence suggests a deliberate backlog-release strategy or rapid affiliate expansion.

Financial extortion; opportunistic targeting across global sectors

Polygon smart contract-based C2 proxy rotation (EtherHiding), BYOVD EDR termination via vulnerable Baidu driver (BdApiUtil.sys, CVE-2024-51324), Windows shadow copy deletion, PowerShell-based service termination prior to encryption, Session messaging app for victim negotiation (no public DLS initially), double extortion with data theft threats

PROFESSIONAL SERVICES
TECHNOLOGY
MANUFACTURING
FINANCIAL SERVICES
LOGISTICS

C++ ransomware binary targeting Windows systems; Polygon (MATIC) blockchain smart contracts for C2 proxy storage/rotation; Session end-to-end encrypted messaging for victim communications; newly activated clearnet DLS (deadlock.liveblog365[.]com — observed June 16, 2026); no known affiliate program initially (possible shift in mid-2026)

FILE DATE: JUL 2025
Initial Stealth Operations
DeadLock launched as a low-profile operation, using Polygon smart contracts for C2 and avoiding public leak sites, accumulating victims quietly while staying off major threat tracking radars.
FILE DATE: JUN 2026
Mass Victim Disclosure Surge
DeadLock broke 11 months of silence with 75–81 named victims posted █████████████ leaping to second place globally and drawing major analyst attention for its blockchain-based C2 and kernel-level EDR evasion capabilities.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn