DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // DEADLOCK-RAASFIRST SEEN: JUL 2025

DeadLock

ALSO KNOWN AS: Deadlock Ransomware
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown
ATTRIBUTION:ORGANIZED CRIME
STATUS:● ACTIVE
FIRST OBSERVED:JUL 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL68/100
RESOURCES68/100
PERSISTENCE71/100
STEALTH63/100
IMPACT77/100

DeadLock emerged in July 2025 operating quietly without a data leak site before detonating onto the ransomware leaderboard in June 2026 with 75–81 claimed victims, jumping to second place globally. The group is technically distinguished by its use of Polygon blockchain smart contracts for C2 proxy address rotation (EtherHiding technique), and by kernel-level EDR termination via a BYOVD attack exploiting the vulnerable Baidu Antivirus driver (CVE-2024-51324). Its sudden leap in victim volume in June 2026 after 11 months of relative silence suggests a deliberate backlog-release strategy or rapid affiliate expansion.

Financial extortion; opportunistic targeting across global sectors

Polygon smart contract-based C2 proxy rotation (EtherHiding), BYOVD EDR termination via vulnerable Baidu driver (BdApiUtil.sys, CVE-2024-51324), Windows shadow copy deletion, PowerShell-based service termination prior to encryption, Session messaging app for victim negotiation (no public DLS initially), double extortion with data theft threats

PROFESSIONAL SERVICES
TECHNOLOGY
MANUFACTURING
FINANCIAL SERVICES
LOGISTICS

C++ ransomware binary targeting Windows systems; Polygon (MATIC) blockchain smart contracts for C2 proxy storage/rotation; Session end-to-end encrypted messaging for victim communications; newly activated clearnet DLS (deadlock.liveblog365[.]com — observed June 16, 2026); no known affiliate program initially (possible shift in mid-2026)

FILE DATE: JUL 2025
Initial Stealth Operations
DeadLock launched as a low-profile operation, using Polygon smart contracts for C2 and avoiding public leak sites, accumulating victims quietly while staying off major threat tracking radars.
FILE DATE: JUN 2026
Mass Victim Disclosure Surge
DeadLock broke 11 months of silence with 75–81 named victims posted █████████████ leaping to second place globally and drawing major analyst attention for its blockchain-based C2 and kernel-level EDR evasion capabilities.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn