OFICIAL Microsoft Source

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

What happened
Based on Microsoft Source · Aug 10, 2026

Microsoft reports DeadLock ransomware, a Rust-based encryptor using decentralized infrastructure and double extortion, targeting organizations globally since July 2025.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Source — Microsoft
Key points
·
Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.
·
Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process.
·
This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims.
·
Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.
Key numbers
·
If no elevated privileges are detected, it attempts privilege escalation via a batch script and UAC prompt, retrying up to 10 times if denied.

DeadLock ransomware, first observed in July 2025, employs double extortion by encrypting victim data while threatening to leak stolen information. The operation uses decentralized infrastructure, including the Session messaging network and blockchain-backed services, to maintain resilience in communication, leak-hosting, and negotiation systems. Microsoft has linked DeadLock to affiliates of the Lynx and INC ransomware ecosystems, with over 80 organizations listed on its data leak site as of July 2026, predominantly in Europe.

The DeadLock encryptor includes a resource-aware throttling mechanism to preserve system responsiveness during encryption, alongside geofencing to avoid execution in former Soviet states, CIS-linked countries, and select Middle Eastern regions. It also features a self-deletion mechanism triggered by specific system languages, reducing its footprint in targeted environments. The malware decrypts an embedded configuration blob using XOR decoding with an 8-byte key before proceeding with malicious activities.

Upon execution, DeadLock checks system languages against an exclusion list; if matched, it self-deletes without encryption. If no elevated privileges are detected, it attempts privilege escalation via a batch script and UAC prompt, retrying up to 10 times if denied. With elevated access, it enables multiple privileges to bypass restrictions and maximize file targeting. The malware also empties the recycle bin silently and associates encrypted files with a custom .ico icon via registry modifications.

Before encryption, DeadLock terminates security-related processes and disables services, including Windows Defender, Volume Shadow Copy, and Active Directory services, to disrupt defensive capabilities. It employs three methods to clear, disable, and lock down event logs, eliminating forensic evidence. Selective encryption excludes critical directories and file types to maintain system stability, allowing victims to access ransom instructions while minimizing operational disruption.

Original source → Deals on Clipraptor.com →