Connect with us

Hi, what are you looking for?

Technology

DeadLock Ransomware Group Exploits Polygon Smart Contracts for Proxy Management

DeadLock uses Polygon smart contracts to manage proxy addresses, complicating efforts to block their attacks

The DeadLock ransomware group, which surfaced in July 2025, has gained attention for its innovative exploitation of Polygon blockchain smart contracts. According to a report from cybersecurity firm Group-IB, the group utilizes these smart contracts to manage and frequently rotate proxy server addresses, making it increasingly challenging for cybersecurity defenders to permanently block their malicious infrastructure.

Once a victim”s system is compromised, DeadLock deploys an HTML file that serves as a conduit for messages via the decentralized messaging platform Session. Through embedded JavaScript code, this file queries a designated Polygon smart contract to retrieve the current proxy URL, enabling the transmission of encrypted communications between the victim and the attacker”s Session ID. Notably, these queries are read-only and do not incur any transaction fees, allowing the attackers to maintain operations at no cost.

Group-IB researchers highlighted the unique nature of this technique, which provides attackers with a seemingly limitless array of variations, thus complicating detection efforts. Despite being underreported, this approach is reportedly gaining traction among malicious actors. A separate investigation by Cisco Talos revealed that DeadLock typically gains initial access by exploiting CVE-2024-51324, a vulnerability linked to Baidu Antivirus, employing a method known as “bringing your own vulnerable driver” to disable endpoint detection and response systems.

What sets DeadLock apart from its peers is its departure from the conventional double extortion model commonly adopted by ransomware groups. Instead of operating a data leak site, it threatens to sell stolen data on underground markets while offering victims security reports and a commitment not to re-target them if the ransom is paid. Although Group-IB”s tracking efforts have not connected DeadLock to established ransomware affiliate programs, they identified smart contract copies created and updated between August and November 2025.

Furthermore, the group has successfully tracked its infrastructure through blockchain transactions, revealing distinct funding patterns and active servers. Interestingly, similar techniques have been noted among nation-state actors, with the Google Threat Intelligence Group observing North Korean threat actor UNC5342 using a related method named EtherHiding for malware delivery and cryptocurrency theft since February 2025. EtherHiding involves embedding malicious code, often JavaScript payloads, within public blockchain smart contracts.

As a layer-2 solution built on Ethereum”s infrastructure, Polygon presents both opportunities and risks. While DeadLock remains a low-volume threat at present, experts warn that its innovative techniques highlight a skill set that could pose significant risks if organizations fail to recognize the seriousness of the threat. In response to this evolving landscape, Group-IB advocates for businesses to enhance their security measures, including implementing multifactor authentication, conducting employee training, and maintaining up-to-date data backups. They emphasize the importance of not paying the ransom and instead contacting incident response experts promptly in the event of an attack.

You May Also Like

Top Stories

BitRss provides real-time updates and curated content for the crypto community around the clock

Markets

Bitcoin"s value against gold has reached a critical support level; will it bounce back?

Altcoins

LivLive offers a 200% bonus in its presale, making it a standout option for investors seeking affordable crypto.

Altcoins

Ripple, XRP, and the XRP Ledger are distinct entities crucial for cross-border payments.

Markets

AVAX is currently trading between $21.40 support and $23.50 resistance levels, with potential for short-term recovery.

Markets

Dogecoin"s open interest has fallen to its lowest in six months, signaling potential price volatility ahead.

Business

Ripple"s recent achievements spark discussions on an IPO, though the company denies any immediate plans.

Altcoins

XRP is poised to play a crucial role in a $30 trillion market for tokenized assets, reshaping finance.

Bitcoin

Bitcoin"s price has dropped below the critical $100,000 level, raising concerns among investors.

Markets

Ethereum struggles to maintain a $3.2K floor amidst significant DeFi market outflows and low buying conviction.

Regulation

Nvidia"s stock drops sharply after the US bans AI chip sales to China, impacting growth plans.

Top Stories

A counterfeit Hyperliquid app has been identified, raising concerns over user scams.

Copyright © 2024 COINNEWSBYTE.COM. All rights reserved. This website provides educational content, emphasizing that investing involves risks. Ensure you conduct thorough research before investing and be ready for any potential losses. For those over 18 and interested in gambling: Online gambling laws differ across countries; adhere to your local regulations. By using this site, you agree to our terms, including the presence of affiliate links that do not impact our evaluations. Cryptocurrency offers on this site are not in line with UK financial promotion regulations and are not aimed at UK consumers.