Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

0
High
Published: 08/10/2026 (08/10/2026, 15:00:00 UTC)
Source: Microsoft Security Blog

Description

DeadLock ransomware is a financially motivated malware operation first observed in July 2025 that uses a Rust-based encryptor combined with decentralized infrastructure for victim communications and data leak hosting. It employs double extortion tactics by encrypting victim data and threatening to publicly release stolen information. The ransomware includes resource-aware throttling to maintain system responsiveness and geofencing to avoid execution in certain countries, notably former Soviet and CIS states and select Middle Eastern countries. DeadLock's decentralized recovery infrastructure leverages the Session messaging network and blockchain-backed services to enhance operational resilience and continuity. It has impacted organizations across multiple sectors worldwide, with a significant number of victims in Europe. Microsoft provides detailed technical analysis, indicators of compromise, and mitigation guidance to defend against this threat.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 21:23:35 UTC

Technical Analysis

DeadLock ransomware is an emerging financially motivated threat tracked by Microsoft Threat Intelligence since July 2025. It is distinguished by its use of decentralized infrastructure combining the Session messaging network and blockchain-backed services to support victim communications, data leak hosting, and extortion processes, enhancing resilience against disruption. The ransomware is written in Rust and features resource-aware throttling to reduce system impact during encryption. It implements geofencing based on system language settings to avoid execution in environments linked to former Soviet, CIS, and select Middle Eastern countries. DeadLock operators employ double extortion by encrypting victim environments and threatening data leaks, with over 80 organizations publicly listed as victims by mid-2026. The malware terminates specific processes and services, excludes certain files and directories from encryption, and delivers ransom notes and an interactive recovery chat page. Multiple ransomware groups, including affiliates of Lynx and INC ecosystems, have deployed DeadLock. Microsoft provides comprehensive technical details, detection capabilities, and mitigation recommendations in their security blog.

Potential Impact

DeadLock ransomware encrypts victim data, disrupting business operations, and uses double extortion by threatening to publicly release stolen data, increasing pressure on victims to pay ransom. Its decentralized infrastructure improves the attackers' ability to maintain communication and data leak operations despite disruption attempts, potentially prolonging the attack lifecycle. The ransomware's resource-aware throttling may reduce detection likelihood by maintaining system responsiveness during encryption. Geofencing limits its impact to targeted regions, avoiding certain countries. The broad sector and geographic impact indicate a significant threat to organizations worldwide.

Defensive Guidance

Microsoft provides detection capabilities through Microsoft Defender and detailed indicators of compromise to identify DeadLock ransomware activity. Organizations should apply these detections and follow Microsoft’s mitigation guidance as outlined in their security blog. No official patch or fix exists since this is malware rather than a software vulnerability. Defensive measures should focus on detection, incident response, and recovery planning. The decentralized nature of the ransomware’s infrastructure means disruption efforts may be less effective, so comprehensive defense-in-depth and rapid response are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/","fetched":true,"fetchedAt":"2026-08-10T21:23:12.357Z","wordCount":5546}

Threat ID: 6a7a4144bf8831d53990704d

Added to database: 08/10/2026, 21:23:16 UTC

Last enriched: 08/10/2026, 21:23:35 UTC

Last updated: 08/10/2026, 23:58:23 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses