DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Brief
In this article
- Pre-encryption
- Encryption
- Post-encryption
- Defending against DeadLock ransomware
- Indicators of compromise
Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.
This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims.
