{"id":47002,"date":"2022-06-06T00:00:00","date_gmt":"2022-06-06T00:00:00","guid":{"rendered":"urn:uuid:9d89c67f-1dbd-4311-251d-755263b55541"},"modified":"2022-06-06T00:00:00","modified_gmt":"2022-06-06T00:00:00","slug":"closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/","title":{"rendered":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/f\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/DeadBolt%20Ransomware_641.jpeg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/f\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/DeadBolt%20Ransomware_641.jpeg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The dark blue line in the survival analysis in Figure 8 shows the date range when victims paid the ransom amount. In this analysis, the victims that do not pay the ransom amount are referred to as survivors, while those who do are referred to as terminal. This analysis allows us to better understand the science of ransomware and ransom payout prevention.<\/p>\n<p>We can go further and say that for about 5 to 7.5 bitcoins (roughly US$200,000 to US$300,000 as of this publishing), they would be willing to give away their methods \u2014 we are, however, only taking them for their word, which admittedly is on the charitable side. On the other hand, the charitable assumption on our end allows for this analysis. It\u2019s also possible that DeadBolt actors think that a conversion ratio of 6% (300,000 divided by 4,400,000) is substantial enough to cash out. They obviously know a lot more about payment ratios than we do, because they eventually topped out at 8%.<\/p>\n<p>It\u2019s also clear that they knew in advance that US$300,000 would have been a good, low-risk deal. That in turn suggests that the entire operation cost them less than US$150,000, otherwise their profit margins would be undesirable. However, it\u2019s worth noting that the fact that 92% of victims have chosen not to pay ransom is an enormous success in cybersecurity \u2014 one that we often choose to ignore; instead, we tend to focus on how much ransomware actors have earned in their attacks.<\/p>\n<p>Let\u2019s try to understand the economic damage that DeadBolt has caused as best as we can. Presumably, for those who paid ransom, their financial losses would have been greater than 0.03 bitcoins (roughly US$1,000 at that time of publishing). For those who didn\u2019t pay ransom, we can reasonably assume that their losses were lower, between zero to US$1,000. We can simplify the matter and suggest that their financial losses could be US$500 on the average.<\/p>\n<p>(0.08 4,988 \u00d7 1,000) + (0.92 \u00d7 4,988 \u00d7 500) = 2,693,520<\/p>\n<p>Based on this calculation, DeadBolt causes about US$2,693,520 worth of economic damage to earn US$300,000. It\u2019s also interesting to think that the US$300,000 amount that they are asking for in exchange of the vulnerability details would probably be split among multiple members of the DeadBolt operation. Based on these numbers, DeadBolt actors are running the risk of incarceration for demanding millions of dollars from their victims, for a chance to earn only thousands, which doesn\u2019t seem to be a sensible risk quantification.<\/p>\n<p>Is it about the money, therefore, or about the damage caused? Are DeadBolt actors punishing society at large or just specific vendors? Or does this represent a refined business model that focuses on automation and volume, along with a chance to get a large single payout from affected vendors? These are some of the questions that we are left with after investigating ransomware groups such as DeadBolt.<\/p>\n<h2><span class=\"body-subhead-title\">Security recommendations<\/span><\/h2>\n<p>Users and organizations can keep their NAS devices secure by implementing the following security recommendations:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Regularly update your NAS devices.<\/b> Make sure that the latest patches have been installed as soon as they are available.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Keep NAS devices offline.<\/b> If you need to access your NAS device remotely, do it securely by opting to use either your NAS vendor\u2019s remote access services (which most major NAS vendors offer) or use a virtual private network (VPN) solutions.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Use a strong password and two-factor authentication (2FA).<\/b> Do not use weak passwords or default credentials. If your NAS device supports 2FA, enable it to add an extra layer of protection against brute force attacks.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Keep your connection and ports secure.<\/b> Keep incoming and outgoing traffic secure by enabling HTTPs instead of HTTP. Remember to close all unused communication ports and change default ports.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Shut down or uninstall unused and out-of-date services.<\/b> Remove unused or out-of-date services to reduce the risk of NAS device compromise.<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\">Conclusion<\/span><\/h2>\n<p>Overall, the total ransom amount that was paid was low in comparison to the number of infected devices, which led us to the conclusion that most people didn\u2019t pay the ransom. It\u2019s also worth pointing out that DeadBolt\u2019s ransom amount costs more than the price of a brand-new NAS device, which is possibly why majority of its victims were not willing to pay to keep their data. Presumably, if the cost was higher, even more victims would be less likely to pay. The goal of DeadBolt actors is to infect as many victims as possible to get a decent payout or to get a vendor to pay one of the ransom options to get substantial financial payouts from its attacks.<\/p>\n<p>Even though the vendor master decryption key did not work in DeadBolt\u2019s campaigns, the concept of holding both the victim and the vendors ransom is an interesting approach. It\u2019s possible that this approach will be used in future attacks, especially since this tactic requires a low amount of effort on the part of a ransomware group.<\/p>\n<p>DeadBolt represents several innovations in the ransomware world: It targets NAS devices, has a multitiered payment and extortion scheme, and has a flexible configuration. But perhaps its main contribution to the ransomware ecosystem will be the legacy of its heavily automated approach. There is a lot of attention on ransomware families that focus on big-game hunting and one-off payments, but it\u2019s also important to keep in mind that ransomware families that focus on spray-and-pray types of attacks such as DeadBolt can also leave a lot of damage to end users and vendors.<\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"12\">\n<tr>\n<td><b>SHA-256<\/b><\/td>\n<td><b>Detection<\/b><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>3c4af1963fc96856a77dbaba94e6fd5e13c938e2de3e97bdd76e1fca6a7ccb24<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>80986541450b55c0352beb13b760bbd7f561886379096cf0ad09381c9e09fe5c<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>e16dc8f02d6106c012f8fef2df8674907556427d43caf5b8531e750cf3aeed77<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>acb3522feccc666e620a642cadd4657fdb4e9f0f8f32462933e6c447376c2178<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>14a13534d21d9f85a21763b0e0e86657ed69b230a47e15efc76c8a19631a8d04<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>444e537f86cbeeea5a4fcf94c485cc9d286de0ccd91718362cecf415bf362bcf<\/td>\n<td>Ransom.Linux.DEADBOLT.YXCEP<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span class=\"body-subhead-title\">Yara rules<\/span><\/p>\n<p><span class=\"blockquote\">rule deadbolt_cgi_ransomnote : ransomware {<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; meta:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; description = &#8220;Looks for CGI shell scripts created by DeadBolt&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; author = &#8220;Trend Micro Research&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; date = &#8220;2022-03-25&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;4f0063bbe2e6ac096cb694a986f4369156596f0d0f63cbb5127e540feca33f68&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;81f8d58931c4ecf7f0d1b02ed3f9ad0a57a0c88fb959c3c18c147b209d352ff1&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;3058863a5a169054933f49d8fe890aa80e134f0febc912f80fc0f94578ae1bcb&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;e0580f6642e93f9c476e7324d17d2f99a6989e62e67ae140f7c294056c55ad27&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; strings:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;ACTION=$(get_value \\&#8221;$DATA\\&#8221; \\&#8221;action\\&#8221;)&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;invalid key len&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;correct master key&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;&#8216;{\\&#8221;status\\&#8221;:\\&#8221;finished\\&#8221;}'&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;base64 -d 2&gt;\/dev\/null&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; condition:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; uint32be(0) != 0x7F454C46 \/\/ We are not interested on ELF files here<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; and all of them<\/span><\/p>\n<p><span class=\"blockquote\">}<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;<\/span><\/p>\n<p><span class=\"blockquote\">rule deadbolt_uncompressed : ransomware {<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; meta:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; description = &#8220;Looks for configuration fields in the JSON parsing code&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; author = &#8220;Trend Micro Research&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; date = &#8220;2022-03-23&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;444e537f86cbeeea5a4fcf94c485cc9d286de0ccd91718362cecf415bf362bcf&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;80986541450b55c0352beb13b760bbd7f561886379096cf0ad09381c9e09fe5c&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; hash = &#8220;e16dc8f02d6106c012f8fef2df8674907556427d43caf5b8531e750cf3aeed77&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; strings:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;key\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;cgi_path\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;client_id\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;vendor_name\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;vendor_email\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;vendor_amount\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;payment_amount\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;vendor_address\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;master_key_hash\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;payment_address\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $= &#8220;json:\\&#8221;vendor_amount_full\\&#8221;&#8221;<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp; condition:<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; elf.type == elf.ET_EXEC<\/span><\/p>\n<p><span class=\"blockquote\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; and all of them<\/span><\/p>\n<p><span class=\"blockquote\">}<\/span><\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this report, we investigate the reasons that the DeadBolt ransomware family is more problematic for its victims than other ransomware families that previously targeted NAS devices. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":47003,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9514,9539,9509],"class_list":["post-47002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-iot","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-06T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/f\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/DeadBolt%20Ransomware_641.jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme\",\"datePublished\":\"2022-06-06T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/\"},\"wordCount\":1523,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : IoT\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/\",\"name\":\"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg\",\"datePublished\":\"2022-06-06T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg\",\"width\":641,\"height\":426},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/","og_locale":"en_US","og_type":"article","og_title":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-06-06T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/f\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/DeadBolt%20Ransomware_641.jpeg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme","datePublished":"2022-06-06T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/"},"wordCount":1523,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/06\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : IoT","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/","url":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/","name":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/06\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg","datePublished":"2022-06-06T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/06\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/06\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme.jpg","width":641,"height":426},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Closing the Door: DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47002"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47002\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/47003"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}