Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026

Firstsource Launches Kairos — The Operating System Powering Intelligence That Operates

April 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation
DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation
Security and Privacy

DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation

January 14, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A ransomware operation known as DeadLock has been observed abusing Polygon blockchain smart contracts to manage and rotate proxy server addresses.

DeadLock first appeared in July 2025 and has maintained a relatively low profile since then. It is not linked to known ransomware affiliate programs and does not operate a public data leak site.

Despite the limited number of reported victims, Group-IB researchers said its technical approach deserves attention for its novelty and potential reuse by other threat actors.

New DeadLock Infrastructure

The latest DeadLock samples observed by the cybersecurity firm include an HTML file used to communicate with victims through the Session encrypted messaging platform.

Instead of relying on hard-coded servers, the malware retrieves proxy addresses stored inside a Polygon smart contract. 

Group-IB noted that retrieving data from the blockchain relies on read-only calls that do not generate transactions or incur network fees, a design choice that complicates traditional blocking approaches.

The  JavaScript code found within the calls queries a specific Polygon smart contract to obtain the current proxy URL. That proxy then relays encrypted messages between the victim and the attacker’s Session ID.

Key aspects of the approach include:

  • Decentralized storage of proxy addresses on the Polygon blockchain

  • Fallback mechanisms using multiple RPC endpoints

  • Use of smart contract functions to update infrastructure on demand

Read more on blockchain abuse in cybercrime: Malicious npm Packages Exploit Ethereum Smart Contracts

The research also links multiple smart contracts to a single creator wallet, which was funded shortly before deployment. Transaction history shows the same method being used to set new proxy servers over time, suggesting active management of the infrastructure.

See also  Canadian Sentenced 20 Years in US Prison For Ransomware Attacks

Broader Implications For Defenders

Group-IB said DeadLock also uses AnyDesk as a remote management tool and deploys PowerShell scripts to stop services and delete shadow copies, increasing the impact of encryption.

Victims’ files are renamed with a .dlock extension, and later ransom notes threaten to sell stolen data if payment is not made.

The researchers explained that similar blockchain-based techniques have recently been reported in other campaigns, including cases where smart contracts were used to store malicious payloads or command locations.

While DeadLock remains low volume, its use of Polygon smart contracts demonstrates how decentralized platforms can be repurposed for resilient command-and-control (C2).

The findings suggest that abuse of public blockchains for malware operations is likely to grow, challenging defenders to adapt detection strategies without disrupting legitimate use of decentralized technologies.

Source link

Contracts DeadLock Polygon Proxy Ransomware rotation Smart
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026

Operation Atlantic Seizes $12m in Crypto Losses

April 13, 2026

Bitcoin Depot Reports $3.6m Crypto Theft After System Breach

April 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Over 50% of US Bitcoin Miners to Back New Policy Group

September 19, 2023

Binance withdraws from Netherlands following VASP license snub

June 17, 2023

eToro ending US customers’ access to four cryptocurrencies

June 13, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026

Firstsource Launches Kairos — The Operating System Powering Intelligence That Operates

April 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$75,094.000.42%
  • ethereumEthereum(ETH)$2,346.21-0.57%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.454.13%
  • binancecoinBNB(BNB)$634.591.85%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$89.365.39%
  • tronTRON(TRX)$0.326747-0.39%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.54%
  • dogecoinDogecoin(DOGE)$0.0982333.10%