{"id":61245,"date":"2026-08-10T15:00:00","date_gmt":"2026-08-10T15:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=149064"},"modified":"2026-08-10T15:00:00","modified_gmt":"2026-08-10T15:00:00","slug":"deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/","title":{"rendered":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure"},"content":{"rendered":"<aside class=\"table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents\" id=\"accordion-cc723f83-32b2-4e25-951b-ef92044565aa\" data-bi-an=\"table-of-contents\"> <button class=\"btn btn-collapse\" type=\"button\" aria-expanded=\"true\" aria-controls=\"accordion-collapse-cc723f83-32b2-4e25-951b-ef92044565aa\"> <span class=\"table-of-contents-block__label\">In this article<\/span> <span class=\"table-of-contents-block__current\" aria-hidden=\"true\"><\/span> <svg class=\"table-of-contents-block__arrow\" aria-label=\"Toggle arrow\" width=\"18\" height=\"11\" viewBox=\"0 0 18 11\" fill=\"none\"> <path d=\"M15.7761 11L18 8.82043L9 0L0 8.82043L2.22394 11L9 4.35913L15.7761 11Z\" fill=\"currentColor\" \/> <\/svg> <\/button> <span class=\"table-of-contents-block__progress-bar\"><\/span><br \/>\n<\/aside>\n<p class=\"wp-block-paragraph\">Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.<\/p>\n<p class=\"wp-block-paragraph\">First observed in July 2025, DeadLock operators employ double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of July 2026, the operators have published more than 80 compromised organizations on their data leak site, called the DeadLock blog, with more than half of the claimed victims in Europe. Microsoft identified DeadLock ransomware impacting organizations across information technology (IT), mining, transportation and logistics, manufacturing, hospitality, consumer goods, and other sectors in Europe, Asia, North America, South America, and Africa.<\/p>\n<p class=\"wp-block-paragraph\">The DeadLock encryptor includes a resource-aware throttling mechanism designed to maintain system responsiveness during encryption. In addition to its encryption capabilities, the ransomware also appears to implement language or country-based geofencing designed to avoid running in environments associated with former Soviet and Commonwealth of Independent States (CIS)-linked countries as well as select Middle Eastern countries, a pattern commonly observed among ransomware operators believed to operate from those regions. Together, these capabilities demonstrate how DeadLock combines established <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/tag\/ransomware\/\" target=\"_blank\" rel=\"noopener noreferrer\">ransomware tradecraft<\/a> with decentralized infrastructure designed to improve operational resilience.<\/p>\n<p class=\"wp-block-paragraph\">In this blog, we present a technical analysis of the DeadLock ransomware encryptor, covering its execution flow, defense evasion techniques, encryption design, and post-encryption behaviors, including a decentralized recovery chat system. We also provide indicators of compromise (IOCs), <a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Defender<\/a> detections, and mitigation guidance to help organizations defend against this threat and similar ransomware activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"pre-encryption\">Pre-encryption<\/h2>\n<h3 class=\"wp-block-heading\" id=\"configuration-parsing\">Configuration parsing<\/h3>\n<p class=\"wp-block-paragraph\">Before performing any malicious activity, the DeadLock encryptor decrypts an embedded configuration blob using XOR decoding with an 8-byte key.<\/p>\n<p class=\"wp-block-paragraph\">Below are the malware\u2019s configuration fields and their values.<\/p>\n<figure class=\"wp-block-table\"><\/figure>\n<h3 class=\"wp-block-heading\" id=\"language-geofencing\">Language geofencing<\/h3>\n<p class=\"wp-block-paragraph\">As an early exit check, the malware queries the system\u2019s default and user interface (UI) languages. If either language matches the exclude list in the configuration, the malware self-deletes immediately without performing any encryption.<\/p>\n<p class=\"wp-block-paragraph\">The following languages trigger this exit behavior:<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>LANGID<\/strong><\/td>\n<td><strong>Language<\/strong><\/td>\n<td><strong>Country<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1049<\/td>\n<td>Russian<\/td>\n<td>Russia<\/td>\n<\/tr>\n<tr>\n<td>1058<\/td>\n<td>Ukrainian<\/td>\n<td>Ukraine<\/td>\n<\/tr>\n<tr>\n<td>1059<\/td>\n<td>Belarusian<\/td>\n<td>Belarus<\/td>\n<\/tr>\n<tr>\n<td>1064<\/td>\n<td>Tajik (Cyrillic)<\/td>\n<td>Tajikistan<\/td>\n<\/tr>\n<tr>\n<td>1065<\/td>\n<td>Persian<\/td>\n<td>Iran<\/td>\n<\/tr>\n<tr>\n<td>1067<\/td>\n<td>Armenian<\/td>\n<td>Armenia<\/td>\n<\/tr>\n<tr>\n<td>1068<\/td>\n<td>Azeri&nbsp;(Latin)<\/td>\n<td>Azerbaijan<\/td>\n<\/tr>\n<tr>\n<td>1079<\/td>\n<td>Georgian<\/td>\n<td>Georgia<\/td>\n<\/tr>\n<tr>\n<td>1087<\/td>\n<td>Kazakh<\/td>\n<td>Kazakhstan<\/td>\n<\/tr>\n<tr>\n<td>1088<\/td>\n<td>Kyrgyz<\/td>\n<td>Kyrgyzstan<\/td>\n<\/tr>\n<tr>\n<td>1090<\/td>\n<td>Turkmen<\/td>\n<td>Turkmenistan<\/td>\n<\/tr>\n<tr>\n<td>1114<\/td>\n<td>Syriac<\/td>\n<td>Syria<\/td>\n<\/tr>\n<tr>\n<td>2072<\/td>\n<td>Romanian (Moldova)<\/td>\n<td>Moldova<\/td>\n<\/tr>\n<tr>\n<td>2092<\/td>\n<td>Azeri&nbsp;(Cyrillic)<\/td>\n<td>Azerbaijan<\/td>\n<\/tr>\n<tr>\n<td>2115<\/td>\n<td>Uzbek (Cyrillic)<\/td>\n<td>Uzbekistan<\/td>\n<\/tr>\n<tr>\n<td>8193<\/td>\n<td>Arabic<\/td>\n<td>Oman<\/td>\n<\/tr>\n<tr>\n<td>9217<\/td>\n<td>Arabic (Yemen)<\/td>\n<td>Yemen<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h3 class=\"wp-block-heading\" id=\"command-line-processing-and-privilege-elevation\">Command-line processing and privilege elevation<\/h3>\n<p class=\"wp-block-paragraph\">The encryptor\u2019s behavior branches based on command-line arguments and the current privilege level. If a target directory path is provided as the command-line argument, the malware skips all preparation steps and jumps directly to encryption. This feature allows the operator to invoke the encryptor with specific targets for focused encryption. If no sub-commands are provided and the process is already elevated, the malware proceeds normally through all execution phases.<\/p>\n<p class=\"wp-block-paragraph\">The more interesting case occurs when no command-line argument is provided while the process is not elevated. In this scenario, the malware attempts to gain administrator privileges through a batch-script-based elevation technique. It generates a randomly named <em>.cmd<\/em> file (8 uppercase characters, such as <em>ESYEKQSY.cmd<\/em>) and executes it using <em>ShellExecuteW<\/em> with the <em>RunAs<\/em> verb, which triggers the Windows User Account Control (UAC) consent dialog. If the user denies the prompt, the malware retries up to 10 times before giving up and exiting.<\/p>\n<p class=\"wp-block-paragraph\">During dynamic analysis, the sample did not successfully relaunch itself with elevated privileges. As a result, full pre-encryption preparation appears to require execution from an already elevated context. When invoked with a target path, the malware bypasses preparation and proceeds directly to encrypt accessible files. This behavior is specific to the analyzed sample and may change in later variants.<\/p>\n<h3 class=\"wp-block-heading\" id=\"token-privilege-escalation\">Token privilege escalation<\/h3>\n<p class=\"wp-block-paragraph\">When running with administrator privileges, the malware further expands its access by enabling <em>SeDebugPrivilege<\/em>, <em>SeRestorePrivilege<\/em>, <em>SeBackupPrivilege<\/em>, <em>SeTakeOwnershipPrivilege<\/em>, <em>SeAuditPrivilege<\/em>, and <em>SeSecurityPrivilege<\/em>. These privileges increase the malware\u2019s ability to interact with system processes, protected files, and security-related settings, helping it overcome common access restrictions and maximize the scope of files and resources it can target during the encryption phase.<\/p>\n<h3 class=\"wp-block-heading\" id=\"recycle-bin-emptying\">Recycle bin emptying<\/h3>\n<p class=\"wp-block-paragraph\">The malware silently empties the recycle bin on all drives without any UI or confirmation dialog, eliminating a potential source of file recovery for victims.<\/p>\n<h3 class=\"wp-block-heading\" id=\"custom-icon-registration\">Custom icon registration<\/h3>\n<p class=\"wp-block-paragraph\">To visually brand encrypted files, the malware writes an embedded <em>.ico<\/em> file to <em>C:\\ProgramData\\&lt;UID&gt;.ico<\/em> and registers it as the default icon for files with the extension <em>.dlock<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">To associate the custom icon with encrypted files, the ransomware creates the <em>HKLM\\SOFTWARE\\Classes\\.dlock\\DefaultIcon<\/em> registry key and sets its <em>(Default)<\/em> value to the path of the dropped icon file.<\/p>\n<p class=\"wp-block-paragraph\">Below is the malware\u2019s embedded <em>.ico <\/em>file.<\/p>\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"147\" height=\"147\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg\" alt=\"A lock symbol surrounded by a circular target.\" class=\"wp-image-149079\"><figcaption class=\"wp-element-caption\"><em>Figure 1. DeadLock icon for encrypted files<\/em><\/figcaption><\/figure>\n<h3 class=\"wp-block-heading\" id=\"process-and-service-termination\">Process and service termination<\/h3>\n<p class=\"wp-block-paragraph\">Before starting encryption, the malware terminates processes and disables services that could interfere with file access or provide defensive capabilities. This approach ensures that locked files become accessible for encryption while simultaneously disrupting the environment\u2019s ability to detect, respond to, or recover from the attack.<\/p>\n<p class=\"wp-block-paragraph\">For services, the malware enumerates all active Win32 services and compares them against the stop list in the configuration. For each matching service, DeadLock sets its start type to <em>DISABLED<\/em> and sends a stop command to terminate that service. Notable targets include <em>windefend<\/em> (Windows Defender), <em>vss<\/em>\/<em>swprv<\/em>\/<em>wbengine<\/em> (Volume Shadow Copy and Backup services), <em>mssearch<\/em>, Hyper-V services (<em>vmcompute<\/em>, <em>vmms<\/em>), and Active Directory services (<em>adws<\/em>, <em>ntds<\/em>, <em>kdc<\/em>). Below is the full service stop list in the malware configuration:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-2.-Service-stop-list.webp\" alt=\"A list of service names and their corresponding service types, primarily related to Windows services.\" class=\"wp-image-149080 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-2.-Service-stop-list.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 2. Service stop list<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">For processes, the malware enumerates all running processes and terminates any matching its stop list while skipping its own process ID. Targeted processes include security tools (<em>msmpeng<\/em>, <em>securityhealthservice<\/em>, <em>smartscreen<\/em>), backup and cloud sync applications (<em>onedrive<\/em>, <em>dropbox<\/em>, <em>googledrivefs<\/em>, <em>owncloud<\/em>), remote access tools (<em>anydesk<\/em>, <em>putty<\/em>, <em>mstsc<\/em>, <em>rustdesk<\/em>), shell and system processes (<em>explorer<\/em>, <em>powershell<\/em>, <em>taskmgr<\/em>, <em>cmd<\/em>), and search\/indexing services. Below is the full process stop list in the malware configuration:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-13.webp\" alt=\"A list of various Windows processes and system components.\" class=\"wp-image-149073 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-13.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 3. Process stop list<\/em><\/figcaption><\/figure>\n<h3 class=\"wp-block-heading\" id=\"event-log-clearing\">Event log clearing<\/h3>\n<p class=\"wp-block-paragraph\">To eliminate forensic evidence, the malware employs three complementary methods that collectively ensure every event log channel on the system is cleared of existing entries, disabled from recording future events, and has its access permissions locked down:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Direct clearing:<\/strong> Clears the following log channels via the classic Event Log API: <em>Application<\/em>, <em>Security<\/em>, <em>Setup<\/em>, <em>Servicing<\/em>, <em>Eventlog<\/em>, <em>Forwarded Events<\/em>, <em>Windows PowerShell<\/em>, and <em>System<\/em>.<\/li>\n<li class=\"wp-block-list-item\"><strong>Registry-based disabling: <\/strong>Enumerates every sub-key under <em>HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WINEVT\\Channels<\/em>. For each channel, sets <em>Enabled<\/em> to 0 (disabling all future logging) and overwrites <em>ChannelAccess<\/em> with a restrictive Security Descriptor Definition Language (SDDL) string that limits access to SYSTEM, built-in administrators, and local admin.<\/li>\n<li class=\"wp-block-list-item\"><strong>Modern API enumeration: <\/strong>Uses <em>wevtapi.dll<\/em> to enumerate all registered event log channel paths (including custom application channels not in the hardcoded list) before clearing each one.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">By combining API-based clearing, registry manipulation, and full channel enumeration, the malware covers multiple log sources, including third-party application logs and custom diagnostic channels, to minimize existing forensic evidence on the infected device.<\/p>\n<h3 class=\"wp-block-heading\" id=\"directory-traversal\">Directory traversal<\/h3>\n<p class=\"wp-block-paragraph\">To maintain system stability and ensure the victim can access ransom instructions, the malware excludes specific directories, file extensions, and file names from encryption. This selective encryption model is a common ransomware design pattern where the system must remain operational enough for the victim to receive instructions and facilitate payment.<\/p>\n<p class=\"wp-block-paragraph\">Extensions and file names from the configuration\u2019s file exclude list are skipped during encryption:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-4.-List-of-skipped-extensions-and-file-names.webp\" alt=\"A list of file extensions and system files related to Windows operating system. \" class=\"wp-image-149081 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-4.-List-of-skipped-extensions-and-file-names.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 4. List of skipped extensions and file names<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">For directory processing, the malware uses a two-tier directory exclusion system applied at different stages of the encryption pipeline. Tier 1 provides rough filtering that saves significant time by avoiding traversal overhead, while tier 2 provides granular path-specific exclusions within directories that are traversed. Both prevent encryption, but they operate at different stages of the traversal pipeline.<\/p>\n<p class=\"wp-block-paragraph\">In its pre-traversal phase (tier 1), the malware checked at the drive batch level before threads are spawned for traversal. If a top-level directory matches against the configured directory exclude list (<em>\\users\\*\\appdata<\/em>, <em>program files (x86)\\<\/em>, <em>program files\\<\/em>, and <em>programdata\\<\/em>), the entire tree is skipped without being walked.<\/p>\n<p class=\"wp-block-paragraph\">In its during-traversal phase (tier 2), the malware checked the file name during recursive directory enumeration and applied to both subdirectories and files as they are encountered. In this tier, the directory and file names are checked against the configured sub-path exclude list below.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-5.-Sub-path-exclude-list.webp\" alt=\"A list of file paths and folders typically associated with the Windows operating system.\" class=\"wp-image-149082 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-5.-Sub-path-exclude-list.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 5. Sub-path exclude list<\/em><\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"encryption\">Encryption<\/h2>\n<h3 class=\"wp-block-heading\" id=\"resource-aware-throttling\">Resource-aware throttling<\/h3>\n<p class=\"wp-block-paragraph\">One of the more distinctive aspects of the DeadLock encryptor is its resource-aware throttling mechanism, designed to keep the infected system responsive during encryption. The malware spawns a dedicated monitoring\/dispatch thread per drive batch that acts as a gatekeeper for file encryption dispatch. Before dispatching each new file to be encrypted, this thread polls system resource utilization and checks against hardcoded thresholds:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Polls memory and CPU idle before each file dispatch<\/li>\n<li class=\"wp-block-list-item\">Calculates memory usage percentage and CPU idle percentage<\/li>\n<li class=\"wp-block-list-item\">If memory usage exceeds 29% or CPU load exceeds 70% (idle &lt; 30%), the dispatch thread pauses via a waitable timer and retries until resources return below thresholds<\/li>\n<li class=\"wp-block-list-item\">Once thresholds are within limits, atomically sets a dispatch flag on the work queue and signals waiting encrypting worker threads<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">With this mechanism, worker threads already encrypting files are not interrupted, and only the dispatch of new files is gated. This means partially encrypted files are expected to complete, and the throttling manifests as reduced parallelism rather than stop\/start behavior. This approach can prevent system hangs that would alert the user and reduce the likelihood of behavioral detection by maintaining normal-looking resource consumption patterns.<\/p>\n<h3 class=\"wp-block-heading\" id=\"thread-architecture\">Thread architecture<\/h3>\n<p class=\"wp-block-paragraph\">For the encryption work itself, the malware spawns directory processing threads, with the thread count being 2 times the CPU core number. Each thread recursively traverses directories, dropping ransom notes and dispatching files for encryption. Individual file encryption threads are tasked with handling the actual cryptographic operations.<\/p>\n<h3 class=\"wp-block-heading\" id=\"cryptographic-scheme\">Cryptographic scheme<\/h3>\n<p class=\"wp-block-paragraph\">The DeadLock ransomware implements a hybrid cryptographic design that combines Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher for file encryption. Key encapsulation uses the Networking and Cryptography Library (NaCl) <em>crypto_box <\/em>construction, which pairs an asymmetric key exchange with authenticated encryption to securely wrap each file\u2019s symmetric key.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"3\">\n<tr>\n<td><strong>Layer<\/strong><\/td>\n<td><strong>Algorithm<\/strong><\/td>\n<td><strong>Purpose<\/strong><\/td>\n<\/tr>\n<tr>\n<td>File content encryption<\/td>\n<td>XChaCha20<\/td>\n<td>Symmetric stream cipher<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Key encapsulation<\/td>\n<td>Curve25519 Elliptic Curve Diffie-Hellman (ECDH) + XSalsa20-Poly1305<\/td>\n<td>Asymmetric key wrapping (NaCl <em>crypto_box<\/em>)<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Random generation<\/td>\n<td>Windows CryptoAPI<\/td>\n<td>All key material random generation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">The configuration\u2019s operator public key <em>03bf50bbf97c4e951e66ff12b689a37a3ce675b4921e254eae76da77573843e4a9<\/em> is 33 bytes. The leading <em>03<\/em> byte is a SEC1 compressed point format prefix borrowed from Bitcoin\/secp256k1. The malware validates this prefix byte against a lookup table that accepts <em>00<\/em>, <em>02<\/em>, <em>03<\/em>, <em>04<\/em>, and <em>05<\/em>, mapping each to an expected key length.<\/p>\n<p class=\"wp-block-paragraph\">After format validation, only the remaining 32 bytes are used in the actual Curve25519 ECDH scalar multiplication. This SEC1 prefix is non-standard for Curve25519, which natively uses bare 32-byte keys, and the malware author has likely adopted it for format versioning across their builder and decryptor tooling.<\/p>\n<h3 class=\"wp-block-heading\" id=\"per-file-encryption-process\">Per-file encryption process<\/h3>\n<p class=\"wp-block-paragraph\">For each target file, the malware performs the following sequence of operations:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Rename the target file from <em>&lt;filename&gt;<\/em> to <em>&lt;filename&gt;.&lt;UID&gt;.dlock<\/em><\/li>\n<li class=\"wp-block-list-item\">Open the renamed file and retrieve file size\/attributes<\/li>\n<li class=\"wp-block-list-item\">Clear the system attribute if <em>FILE_ATTRIBUTE_SYSTEM<\/em> is set<\/li>\n<li class=\"wp-block-list-item\">Determine the encryption strategy based on file size (see <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/10\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#_File_size-based_encryption\">File size-based encryption strategy<\/a>)<\/li>\n<li class=\"wp-block-list-item\">Generate cryptographic material:<\/li>\n<li class=\"wp-block-list-item\">32-byte random XChaCha20 key<\/li>\n<li class=\"wp-block-list-item\">24-byte random XChaCha20 nonce (first 16 bytes for HChaCha20 subkey derivation, last 8 bytes as stream nonce)<\/li>\n<li class=\"wp-block-list-item\">32-byte random ephemeral Curve25519 private key<\/li>\n<li class=\"wp-block-list-item\">12-byte random file tag (only the first byte is functionally referenced by the encryptor to derive padding length; the remaining 11 bytes serve as a random file identifier written to the cleartext footer, likely used by the decryptor for file correlation\/tracking)<\/li>\n<li class=\"wp-block-list-item\">1\u201310 bytes random padding (<em>length = file_tag[0] % 10 + 1<\/em>)<\/li>\n<li class=\"wp-block-list-item\">Perform Curve25519 ECDH: Multiply the ephemeral private key by the attacker\u2019s embedded public key to derive a shared secret<\/li>\n<li class=\"wp-block-list-item\">Build metadata plaintext: XChaCha20 key + 24-byte XChaCha20 nonce + random padding + <em>dDlK<\/em> magic + optional <em>FA<\/em> flag + chunk parameters<\/li>\n<li class=\"wp-block-list-item\">Encrypt metadata using <em>crypto_box<\/em> (XSalsa20-Poly1305) with the ECDH shared secret and a zero nonce<\/li>\n<li class=\"wp-block-list-item\">Encrypt file content using XChaCha20 with the generated key and 24-byte nonce<\/li>\n<li class=\"wp-block-list-item\">Append the encrypted footer\/metadata to the end of the file<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">The use of a zero <em>crypto_box<\/em> nonce is worth noting. This is cryptographically safe because each file generates a unique ephemeral Curve25519 keypair, which produces a unique ECDH shared secret per file. With this, a constant zero nonce never repeats with the same key.<\/p>\n<p class=\"wp-block-paragraph\">The entire design ensures that each file is encrypted with a distinct key derived from a per-file ephemeral key exchange, eliminating any possibility of key reuse across files. Overall, the cryptographic construction is sound and does not present a practical path to decryption without the attacker\u2019s private key.<\/p>\n<h3 class=\"wp-block-heading\" id=\"file-size-based-encryption-strategy\">File size-based encryption strategy<\/h3>\n<p class=\"wp-block-paragraph\">To balance encryption thoroughness with speed, the malware implements a tiered encryption policy based on file size. The encryption rule in the configuration <em>1000,05052429880,025124288000,010524288000,F991114288000<\/em> encodes this policy. Each comma-separated entry is parsed by splitting at position 3: the first 3 characters represent the encryption percentage (decimal), and the remaining characters represent the file size threshold (decimal bytes). The special prefix <em>F<\/em> replaces the percentage field with a chunked-full mode.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"5\">\n<tr>\n<td><strong>Rule<\/strong><\/td>\n<td><strong>Encryption percent<\/strong><\/td>\n<td><strong>File size threshold<\/strong><\/td>\n<td><strong>Behavior<\/strong><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>1000<\/td>\n<td>100%<\/td>\n<td>\u2265 0 bytes<\/td>\n<td>Default: encrypt entire file<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>05052429880<\/td>\n<td>50%<\/td>\n<td>\u2265 ~50 MB<\/td>\n<td>Encrypt 50% of file in distributed chunks<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>025124288000<\/td>\n<td>25%<\/td>\n<td>\u2265 ~118 MB<\/td>\n<td>Encrypt 25% in distributed chunks<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>010524288000<\/td>\n<td>10%<\/td>\n<td>\u2265 ~500 MB<\/td>\n<td>Encrypt 10% in distributed chunks<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>F991114288000<\/td>\n<td>Chunked<\/td>\n<td>\u2265 ~1 GB<\/td>\n<td>Special full-chunk mode with calculated intervals<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Rules are evaluated in order, and the last matching rule wins. For example, when the malware processes a 2 GB file, all rules match, but the final <em>F99\u2026<\/em> entry will determine the encryption behavior.<\/p>\n<p class=\"wp-block-paragraph\">For partial encryption, the malware calculates:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Total bytes to encrypt = <em>ceil(file_size \u00d7 (percentage \/ 100))<\/em><\/li>\n<li class=\"wp-block-list-item\">Encrypted block count = <em>ceil(total_bytes_to_encrypt \/ 512)<\/em><\/li>\n<li class=\"wp-block-list-item\">Skip interval = <em>floor((file_size \u2212 total_bytes_to_encrypt) \/ encrypted_block_count)<\/em><\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">This creates an intermittent encryption pattern where 512-byte blocks are encrypted at regular intervals throughout the file. The result is a file that is rendered unusable while requiring only a fraction of the time needed for full encryption. This is a crucial optimization for the ransomware when targeting large files such as databases, virtual machine images, and backups.<\/p>\n<p class=\"wp-block-paragraph\">After encryption, the malware appends a structured metadata blob to the end of each file. This footer contains all the information the decryptor needs to reverse the encryption, along with markers for format validation:<\/p>\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-2.-DeadLock-file-footer.webp\" alt=\"A detailed structure of a cryptographic message, including encryption, authentication, and various data types arranged in a hierarchical format.\" class=\"wp-image-149083 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-2.-DeadLock-file-footer.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 6. DeadLock file footer<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The footer serves several important functions:<\/p>\n<p class=\"wp-block-paragraph\"><strong>Key and nonce reconstruction:<\/strong> The cleartext ephemeral Curve25519 public key (33 bytes) at the end of the footer allows the decryptor to recompute the ECDH shared secret and open the <em>crypto_box<\/em> to recover the XChaCha20 key and nonce used for file content encryption.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Inner <\/strong><strong><em>dDlK<\/em> magic (decryption validation):<\/strong> After the decryptor opens the <em>crypto_box<\/em>, it checks for the <em>dDlK<\/em> marker at the expected offset (32 + 24 + <em>padding_length<\/em> bytes into the plaintext) to confirm the correct private key was used and that decryption succeeded. While the Poly1305 Message Authentication Code (MAC) already provides cryptographic integrity verification, this marker offers a fast format-level sanity check.<\/p>\n<p class=\"wp-block-paragraph\"><strong><em>FA<\/em> flag (decryption mode indicator):<\/strong> This flag is used by the decryptor to determine which read strategy to use when reversing the encryption. It is present when the file was encrypted using sequential\/contiguous block encryption, and absent when intermittent\/skip encryption was used. Specifically, <em>FA<\/em> is appended in two cases:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>F-prefix rule matched:<\/strong> When the file size triggers the <em>F991114288000<\/em> config entry (the special chunked-full mode), the <em>FA<\/em> flag is always set.<\/li>\n<li class=\"wp-block-list-item\"><strong>Percentage rule with zero skip interval:<\/strong> When a percentage-based rule matches but the calculated skip interval between encrypted chunks works out to zero (meaning the percentage effectively covers the entire file), <em>FA<\/em> is also set.<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">Without this flag, the 8-byte chunk parameters in the footer would be ambiguous as they could represent either a block count or a skip interval. The <em>FA<\/em> flag resolves this ambiguity and enables the decryptor to correctly reconstruct the original file.<\/p>\n<p class=\"wp-block-paragraph\"><strong>File identifier\/format tag:<\/strong> The 12-byte random value in the cleartext footer serves as a file identifier (with the first byte used to derive the padding length inside the encrypted payload).<\/p>\n<h2 class=\"wp-block-heading\" id=\"post-encryption\">Post-encryption<\/h2>\n<h3 class=\"wp-block-heading\" id=\"wallpaper\">Wallpaper<\/h3>\n<p class=\"wp-block-paragraph\">As an immediate visual indicator of compromise, the malware generates a custom BMP wallpaper file at runtime using the victim\u2019s screen resolution. Below is an example of the generated BMP wallpaper:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-7.-DeadLock-wallpaper.webp\" alt=\"DeadLock wallpaper stating the infrastructure is DeadLocked with a note to open the file HOW_RECOVER .< UID>.txt for instructions to recover.&#8221; class=&#8221;wp-image-149084 webp-format&#8221; srcset data-orig-src=&#8221;https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-7.-DeadLock-wallpaper.webp&#8221;><figcaption class=\"wp-element-caption\"><em>Figure 7. DeadLock wallpaper<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The wallpaper is written to <em>C:\\ProgramData\\&lt;UID&gt;.bmp<\/em> (on Vista and later) or <em>C:\\Documents and Settings\\All Users\\Application Data\\&lt;UID&gt;.bmp<\/em> (on XP), set as the desktop background, and persisted in the registry at <em>HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Wallpaper<\/em>.<\/p>\n<h3 class=\"wp-block-heading\" id=\"ransom-notes-deployment\">Ransom notes deployment<\/h3>\n<p class=\"wp-block-paragraph\">After encrypting files, the malware deploys two types of ransom notes, each with distinct deployment logic and purpose:<\/p>\n<p class=\"wp-block-paragraph\"><strong>Text note (<em>HOW_RECOVER.&lt;UID&gt;.txt<\/em>): <\/strong>The text note is dropped into every encrypted directory, but with a notable timing behavior: it is only deployed during the second pass of the directory processing loop. The malware iterates over drive batches multiple times, and the text note drop is gated by an iteration counter. On the first pass, the text note is suppressed, likely to prioritize encryption speed before littering the file system with ransom note files. For defenders and analysts, this has a practical implication: if testing with a minimal drive configuration that only triggers a single iteration, the text note will never appear.<\/p>\n<p class=\"wp-block-paragraph\">Below is the text note content from the malware\u2019s configuration.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-8.-DeadLock-text-ransom-note.webp\" alt=\"A ransom note from a cybercriminal demanding payment to decrypt stolen data and provide a security report.\" class=\"wp-image-149085 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-8.-DeadLock-text-ransom-note.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 8. DeadLock text ransom note<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\"><strong>HTML note (<em>RECOVERY_CHAT.&lt;UID&gt;.html<\/em>): <\/strong>This file is dropped to all drive root directories and all <em>Desktop<\/em> folders. Unlike the text note, the HTML note is a full interactive web application with a self-contained single-page application that implements end-to-end encrypted chat, a paginated data leak blog, and a file browser, all without requiring a traditional backend server. The technical architecture of this recovery chat system is detailed in <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/10\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#_Recovery_chat:_Technical\">Recovery chat: Technical architecture<\/a>.<\/p>\n<h3 class=\"wp-block-heading\" id=\"recovery-chat-technical-architecture\">Recovery chat: Technical architecture<\/h3>\n<p class=\"wp-block-paragraph\">The most distinctive feature of the DeadLock ransomware is its recovery chat system. The <em>RECOVERY_CHAT.&lt;UID&gt;.html<\/em> file is a self-contained HTML application that implements a full end-to-end encrypted chat system, a paginated data leak blog, and a file browser, all without requiring a traditional backend server.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-9.-HTML-application-About-page-UI.webp\" alt=\"DeadLock About page telling the victim that all their important files are encrypted by the ransomware, including documents, photos, videos, databases, and other critical data. It tells the victim to contact the operators to receive a decryption key or else the data will be leaked and published on the DeadLock blog.\" class=\"wp-image-149086 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-9.-HTML-application-About-page-UI.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 9. HTML application \u201cAbout\u201d page UI<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The architecture is designed with three decentralized components.<\/p>\n<h4 class=\"wp-block-heading\" id=\"polygon-blockchain-as-configuration-store\">Polygon blockchain as configuration store<\/h4>\n<p class=\"wp-block-paragraph\">Rather than relying on traditional domain-based infrastructure that can be seized or taken offline, the DeadLock operators store configuration data on the Polygon blockchain. Two smart contracts serve as censorship-resistant infrastructure:<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"4\">\n<tr>\n<td><strong>Contract<\/strong><\/td>\n<td><strong>Address<\/strong><\/td>\n<td><strong>Function selector<\/strong><\/td>\n<td><strong>Purpose<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Chat proxy<\/td>\n<td>0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe<\/td>\n<td>0x933a9ce8<\/td>\n<td>Stores the proxy server URL<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Blog<\/td>\n<td>0x757984507c82c8dA1d3969c535dB5706eEE6426C<\/td>\n<td>0xd4070542<\/td>\n<td>Stores actor\u2019s blog posts<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">The HTML page issues <em>eth_call<\/em> requests to public Polygon Remote Procedure Call (RPC) endpoints (no wallet required with read-only calls) to obtain the proxy server address. The blog contract takes offset and limit parameters (for pagination) and returns structured data including post titles, bodies, timestamps, image URLs, and file attachment links.<\/p>\n<p class=\"wp-block-paragraph\">On-chain storage provides several strategic advantages for the threat actor: the proxy URL can be updated by modifying the smart contract without changing any victim-facing infrastructure, and no domain registration or DNS infrastructure is required. This represents a notable evolution in ransomware infrastructure design.<\/p>\n<p class=\"wp-block-paragraph\">The HTML recovery chat cycles through six public RPC endpoints for redundancy: <em>polygon-bor-rpc.publicnode[.]com<\/em>, <em>polygon.drpc[.]org<\/em>, <em>polygon-pokt.nodies[.]app<\/em>, <em>polygon-rpc[.]com<\/em>, <em>1rpc[.]io\/matic, <\/em>and<em> polygon.meowrpc[.]com<\/em>.<\/p>\n<h4 class=\"wp-block-heading\" id=\"session-network-for-end-to-end-encrypted-chat\">Session network for end-to-end encrypted chat<\/h4>\n<p class=\"wp-block-paragraph\">For victim-operator communication, chat messages are routed through the Session decentralized messenger network, which is an onion-routed, swarm-based messaging protocol that provides anonymity for both parties. The proxy server (whose URL is retrieved from the blockchain) acts as a relay between the victim\u2019s browser and Session swarm nodes.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-12.webp\" alt=\"DeadLock Chat page with instructions for the victim to create a username and password to communicate with the operators.\" class=\"wp-image-149069 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-12.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 10. HTML application \u201dChat\u201d page UI<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\"><strong>Key generation:<\/strong> DeadLock\u2019s design choice is that the victim\u2019s Session identity is derived deterministically from their sign-in credentials. When the victim enters their credentials on the HTML page, the following derivation occurs:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-11.webp\" alt=\"A sequence of steps in cryptographic key generation, including hashing a seed, generating an Ed25519 keypair, converting it to Curve25519 format, and forming a session address.\" class=\"wp-image-149076 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/image-11.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 11. Derivation after victim entered credentials<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">This deterministic derivation means the same credentials always produce the same keypair, and no account registration is needed as the victim\u2019s Session identity exists only when they enter the correct credentials. If the victim forgets their credentials, the identity is unrecoverable (as stated by the actor in the chat UI). The 05 prefix is Session\u2019s standard network identifier for user accounts.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Sending a message:<\/strong> The following sequence occurs when a message is sent:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Encode the body and timestamp as protobuf<\/li>\n<li class=\"wp-block-list-item\">Create an actor message and a self-sync copy<\/li>\n<li class=\"wp-block-list-item\">Pad plaintext to 160-byte boundary<\/li>\n<li class=\"wp-block-list-item\">Sign the padded content and key context with Ed25519<\/li>\n<li class=\"wp-block-list-item\">Append the sender public key and signature<\/li>\n<li class=\"wp-block-list-item\">Seal each payload with the recipient\u2019s Curve25519 key<\/li>\n<li class=\"wp-block-list-item\">Wrap in Session\u2019s onion request protobuf format (verb: <em>PUT<\/em>, path: <em>\/api\/v1\/message<\/em>)<\/li>\n<li class=\"wp-block-list-item\">Ask the proxy to submit both copies to their respective swarms<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\"><strong>Receiving a message:<\/strong> The following sequence occurs when a message is received:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Sign <em>\u201cretrieve\u201d + timestamp<\/em> with the victim\u2019s Ed25519 key<\/li>\n<li class=\"wp-block-list-item\">Select a node associated with the victim\u2019s own swarm<\/li>\n<li class=\"wp-block-list-item\">Ask<em> the proxy to poll for messages addressed to that identity<\/em><\/li>\n<li class=\"wp-block-list-item\">Open each sealed box with the victim\u2019s Curve25519 keypair<\/li>\n<li class=\"wp-block-list-item\">Remove the appended public key and signature<\/li>\n<li class=\"wp-block-list-item\">Strip padding, decode protobuf, and extract the message body<\/li>\n<\/ol>\n<h4 class=\"wp-block-heading\" id=\"data-leak-blog-and-wasabi-file-hosting\">Data leak blog and Wasabi file hosting<\/h4>\n<p class=\"wp-block-paragraph\">The recovery chat page also provides access to a data leak blog whose content is stored on the Polygon blockchain.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-12.-Redacted-HTML-app-Blog-page-UI.webp\" alt=\"DeadLock Blog page displaying redacted, leaked files published on the DeadLock blog.\" class=\"wp-image-149087 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-12.-Redacted-HTML-app-Blog-page-UI.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 12. Redacted HTML app \u201cBlog\u201d page UI<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Blog posts retrieved from the smart contract support BBCode formatting, image galleries, and file attachments using either direct URLs or Wasabi protocol links that open an in-browser file explorer. The HTML application contains a full Amazon Web Services (AWS) S3-compatible file browser that parses the Wasabi credentials from the URI, generates AWS4-HMAC-SHA256 signed requests, lists bucket contents with folder navigation, and generates pre-signed download URLs for individual files. This allows the attacker to host stolen data on Wasabi and provide victims or the public with browsable access to the leaked files without running a web server.<\/p>\n<h4 class=\"wp-block-heading\" id=\"infrastructure-resilience-summary\">Infrastructure resilience summary<\/h4>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-8.-HTML-recovery-chat-infrastructure-summary-scaled.webp\" alt=\"HTML recovery chat infrastructure showing how the Polygon RPC communicates with Smart contracts, Proxy server communicates with Session network, and Wasabi S3 with file browser.\" class=\"wp-image-149088 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-8.-HTML-recovery-chat-infrastructure-summary-scaled.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 13. HTML recovery chat infrastructure summary<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The architecture is significantly more resilient to takedown and censorship efforts, but it is not independent of off-chain infrastructure:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Proxy replacement:<\/strong> The actor can update the on-chain proxy URL without changing the HTML<\/li>\n<li class=\"wp-block-list-item\"><strong>On-chain persistence:<\/strong> Contract-stored blog data is resistant to conventional hosting takedowns<\/li>\n<li class=\"wp-block-list-item\"><strong>RPC dependency:<\/strong> The page still requires access to at least one public Polygon RPC endpoint<\/li>\n<li class=\"wp-block-list-item\"><strong>Proxy dependency:<\/strong> Chat access depends on the current custom proxy remaining reachable<\/li>\n<li class=\"wp-block-list-item\"><strong>Storage dependency:<\/strong> Images and leaked files can be removed from CDN or Wasabi hosting<\/li>\n<li class=\"wp-block-list-item\"><strong>Session resilience:<\/strong> Distributed swarm storage reduces reliance on a single messaging server<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">This infrastructure model represents a meaningful evolution from traditional ransomware communication channels and poses new challenges for takedown efforts.<\/p>\n<h3 class=\"wp-block-heading\" id=\"self-deletion\">Self-deletion<\/h3>\n<p class=\"wp-block-paragraph\">As a final cleanup step after encryption completes, the malware creates a batch to delete its own binary from disk. The cleanup batch loops until it successfully deletes the malware binary, then removes itself:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-14.-Self-deleting-batch-loop.webp\" alt=\"Self deleting batch loop script\" class=\"wp-image-149089 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-14.-Self-deleting-batch-loop.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 14. Self-deleting batch loop<\/em><\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"defending-against-deadlock-ransomware\">Defending against DeadLock ransomware<\/h2>\n<p class=\"wp-block-paragraph\">Microsoft recommends the following mitigations to reduce the impact of this threat.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Read&nbsp;the&nbsp;<a href=\"https:\/\/security.microsoft.com\/threatanalytics3\/b42038f7-a361-40c0-bcaf-5dbb63f33dc3\/analystreport\" target=\"_blank\" rel=\"noreferrer noopener\">human-operated ransomware threat overview<\/a>&nbsp;for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/configure-block-at-first-sight-microsoft-defender-antivirus\">cloud-delivered protection<\/a>&nbsp;in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques.&nbsp;Cloud-based machine learning protections block a huge majority of new and unknown variants.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Run&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/edr-in-block-mode\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection and response (EDR) in block mode<\/a>&nbsp;so that Microsoft Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode. EDR in&nbsp;block mode works behind the scenes to remediate malicious artifacts that are detected post-breach.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/prevent-changes-to-security-settings-with-tamper-protection\">tamper protection<\/a>&nbsp;features to prevent attackers from stopping security services. In addition to tamper protection, you can also&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/configure-real-time-protection-microsoft-defender-antivirus\">enable and configure Microsoft Defender Antivirus always-on protection in Group Policy<\/a>.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Configure&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/automated-investigations\">investigation and remediation<\/a>&nbsp;in full automated mode to let Microsoft&nbsp;Defender for&nbsp;Endpoint take immediate action on alerts to resolve breaches, significantly reducing alert volume.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Configure&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/configure-attack-disruption\">automatic attack disruption<\/a>&nbsp;in Microsoft Defender XDR. Automatic attack disruption is designed to&nbsp;contain&nbsp;attacks in progress, limit the impact on an organization\u2019s assets, and&nbsp;provide more time for security teams&nbsp;to remediate the attack fully.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">To help preserve existing systems&nbsp;in the event of&nbsp;a ransomware attack,&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/controlled-folders\">configure a Controlled Folder Access (CFA) policy<\/a>&nbsp;to be as strict as possible. CFA protects valuable data from threats like ransomware by preventing&nbsp;write&nbsp;access to common system folders; more folders can also be added. Establishing this policy ahead&nbsp;of a&nbsp;ransomware event can enable organizations to respond quickly to ransomware signals, deploying the CFA policy to limit the destructive impact of an active attack. In certain instances, a CFA policy can also be&nbsp;leveraged&nbsp;proactively on specific sensitive assets that will not be negatively&nbsp;impacted&nbsp;by restrictive protections. Use&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/overview-attack-surface-reduction\">audit mode<\/a>&nbsp;to evaluate the impact&nbsp;to&nbsp;your organization in these cases.&nbsp;<\/li>\n<li class=\"wp-block-list-item\">Microsoft Defender XDR customers can turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/attack-surface-reduction\">attack surface reduction rules<\/a>&nbsp;to prevent several of the infection vectors of this threat. These rules, which can be configured by any user, offer significant hardening against targeted attacks. In observed attacks, Microsoft customers who had the following rules turned on could mitigate the attack in the&nbsp;initial&nbsp;stages and prevent hands-on-keyboard activity:&nbsp;&nbsp; <\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">You can assess how an attack surface reduction rule might&nbsp;impact&nbsp;your network by opening the&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-vulnerability-management\/tvm-security-recommendation\">security recommendation<\/a>&nbsp;for that rule in Vulnerability management. In the Recommendation details pane, check the user impact to&nbsp;determine&nbsp;what percentage of your devices can accept a new policy enabling the rule in blocking mode without adverse impact to user productivity.&nbsp;&nbsp;&nbsp;<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-detections\">Microsoft Defender detections<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\">Microsoft Defender<\/a> customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<h4 class=\"wp-block-heading\" id=\"microsoft-defender-antivirus\">Microsoft Defender Antivirus<\/h4>\n<p class=\"wp-block-paragraph\">Microsoft Defender Antivirus detects threat components as the following malware:<\/p>\n<h4 class=\"wp-block-heading\" id=\"microsoft-defender-for-endpoint\">Microsoft Defender for Endpoint<\/h4>\n<p class=\"wp-block-paragraph\">The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Ransomware-linked threat actor detected<\/li>\n<li class=\"wp-block-list-item\">Ransomware behavior detected in the file system<\/li>\n<li class=\"wp-block-list-item\">Possible ransomware activity<\/li>\n<li class=\"wp-block-list-item\">File backups were deleted<\/li>\n<li class=\"wp-block-list-item\">Potential human-operated malicious activity<\/li>\n<li class=\"wp-block-list-item\">Possible data exfiltration<\/li>\n<li class=\"wp-block-list-item\">Suspicious wallpaper change<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The following alerts might indicate threat activity associated with DeadLock ransomware if Defender for Endpoint is set to block mode.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">\u2018DeadLock\u2019 ransomware was detected<\/li>\n<li class=\"wp-block-list-item\">\u2018DeadLock\u2019 ransomware was prevented<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\" id=\"microsoft-defender-for-cloud-apps\">Microsoft Defender for Cloud Apps<\/h4>\n<p class=\"wp-block-paragraph\">The following alert might indicate threat activity associated with this threat. This alert, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Ransomware activity<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h4>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/ai-machine-learning\/microsoft-security-copilot\">Microsoft Security Copilot<\/a> is <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\">embedded in Microsoft Defender<\/a> and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.<\/p>\n<p class=\"wp-block-paragraph\">Customers can also <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-agents-defender\">deploy AI agents<\/a>, including the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/agents-overview\">Microsoft Security Copilot agents<\/a>, to perform security tasks efficiently:<\/p>\n<p class=\"wp-block-paragraph\">Security Copilot is also available as a <a href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/experiences-security-copilot\">standalone experience<\/a> where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/developer\/custom-agent-overview\">developer scenarios<\/a> that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.<\/p>\n<h4 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h4>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can use the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/threat-analytics\">threat analytics<\/a> reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security Copilot customers can also use the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/security-copilot-and-defender-threat-intelligence?bc=%2Fsecurity-copilot%2Fbreadcrumb%2Ftoc.json&amp;toc=%2Fsecurity-copilot%2Ftoc.json#turn-on-the-security-copilot-integration-in-defender-ti\">Microsoft Security Copilot integration<\/a> in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdr\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this threat actor.<\/p>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\">Indicators of compromise<\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"6\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4<\/td>\n<td>SHA-256<\/td>\n<td>DeadLock ransomware encryptor<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>deadlock.liveblog365[.]com<\/em><\/td>\n<td>URL<\/td>\n<td>Leak site domain<\/td>\n<\/tr>\n<tr>\n<td><em>dlock.liveblog365[.]com<\/em><\/td>\n<td>URL<\/td>\n<td>Leak site domain<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion<\/em><\/td>\n<td>URL<\/td>\n<td>Leak site domain<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>deadlockblog.great-site[.]net<\/em><\/td>\n<td>URL<\/td>\n<td>Leak site domain<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>deadlockblog.medianewsonline[.]com<\/em><\/td>\n<td>URL<\/td>\n<td>Leak site domain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h3 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h3>\n<p class=\"wp-block-paragraph\">For the latest security research from the Microsoft Threat Intelligence community, check out the <a href=\"https:\/\/aka.ms\/threatintelblog\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">LinkedIn<\/a>, <a href=\"https:\/\/x.com\/MsftSecIntel\">X (formerly Twitter)<\/a>, and <a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/10\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.<br \/>\nThe post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[5449,711,91,357],"class_list":["post-61245","post","type-post","status-publish","format-standard","hentry","category-microsoft-secure","tag-credential-theft","tag-extortion","tag-ransomware","tag-windows"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"25 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure\",\"datePublished\":\"2026-08-10T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/\"},\"wordCount\":4979,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg\",\"keywords\":[\"Credential Theft\",\"extortion\",\"ransomware\",\"Windows\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/\",\"name\":\"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg\",\"datePublished\":\"2026-08-10T15:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Credential Theft\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/credential-theft\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/","og_locale":"en_US","og_type":"article","og_title":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-08-10T15:00:00+00:00","og_image":[{"width":432,"height":435,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"25 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure","datePublished":"2026-08-10T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/"},"wordCount":4979,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg","keywords":["Credential Theft","extortion","ransomware","Windows"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/","url":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/","name":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg","datePublished":"2026-08-10T15:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#primaryimage","url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg","contentUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/08\/Figure-1.-DeadLock-icon-for-encrypted-files.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Credential Theft","item":"https:\/\/www.threatshub.org\/blog\/tag\/credential-theft\/"},{"@type":"ListItem","position":3,"name":"DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61245","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61245"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61245\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61245"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61245"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}