MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: DeadLock ransomware group exploit Polygon smart contracts for stealth – Cryptopolitan
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$68,520.000.47%
  • ethereumEthereum(ETH)$1,987.731.93%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.481.95%
  • binancecoinBNB(BNB)$626.642.40%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.621.92%
  • tronTRON(TRX)$0.2838651.43%
  • dogecoinDogecoin(DOGE)$0.100592-1.25%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
Smart Contracts

DeadLock ransomware group exploit Polygon smart contracts for stealth – Cryptopolitan

Last updated: January 16, 2026 8:40 am
Published: 1 month ago
Share

Security researchers warn that DeadLock’s blockchain-based techniques mirror methods used by North Korean actors.

DeadLock, a ransomware group that first emerged in July 2025, has made news again, and this time it is for abusing Polygon blockchain smart contracts to manage and rotate proxy server addresses, according to research published by cybersecurity firm Group-IB.

The ransomware operation uses blockchain-based smart contracts to store the group’s proxy server URL, allowing frequent rotation that makes it difficult for defenders to permanently block infrastructure.

After encrypting a victim’s systems, DeadLock drops an HTML file that acts as a wrapper for the decentralized messaging platform, Session.

Embedded JavaScript code within the file queries a specific Polygon smart contract to obtain the current proxy URL, which then relays encrypted messages between the victim and the attacker’s Session ID.

These read-only blockchain calls generate no transactions or fees, making them cost-free for the attackers to maintain.

Group-IB researchers noted that the exploit of smart contracts to deliver proxy addresses is an interesting method where attackers can apply infinite variants of this technique, with imagination being the only limit.

The technique is not well documented and under-reported but its usage is gradually gaining traction in the wild, according to security researchers.

Investigation by Cisco Talos revealed that DeadLock gains initial access by exploiting CVE-2024-51324, a Baidu Antivirus vulnerability, using a technique known as “bringing your own vulnerable driver” to terminate endpoint detection and response processes.

DeadLock is different from most ransomware operations because it abandons the usual double extortion approach and does not have a data leak site where it could publicize attacks.

Instead, the group threatens to sell stolen data on underground markets while offering victims security reports and promises not to re-target them if ransom is paid.

Group-IB’s infrastructure tracking has not drawn any threads between DeadLock and any known ransomware affiliate programs. In fact, the group maintains a relatively low profile. However, they found smart contract copies that were first created and updated in August 2025 and later updated in November 2025.

Group-IB stated that it successfully “tracked its infrastructure through blockchain transactions, revealing funding patterns and active servers.”

Google Threat Intelligence Group observed North Korean threat actor UNC5342 using a related technique called EtherHiding to deliver malware and facilitate cryptocurrency theft since February 2025.

According to Google, “EtherHiding involves embedding malicious code, often in the form of JavaScript payloads, within a smart contract on a public blockchain like BNB Smart Chain or Ethereum.”

Polygon happens to be a layer-2 blockchain that’s built on Ethereum’s layer-1 infrastructure.

While DeadLock remains low volume and low impact, security researchers warn that it applies innovative methods showcasing a skill set that might become dangerous if organizations do not take the threat it poses seriously.

Apart from calling on businesses to be proactive in detecting malware, Group-IB recommended that they should add more layers of security, such as multifactor authentication and credential-based solutions.

The cybersecurity firm also stated that businesses should have a data backup, train their employees, patch up vulnerabilities, and, very importantly, “never pay the ransom” but contact incident response experts as quickly as possible if they ever get attacked.

If you’re reading this, you’re already ahead. Stay there with our newsletter.

Read more on Cryptopolitan

This news is powered by Cryptopolitan Cryptopolitan

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Shiba Inu News: Developers Launch Major Anti-Hack Upgrade for Shibarium
Mirae Asset Global Investments and Ctrl Alt to explore fund tokenization in the UAE – Cryptopolitan
Meet Our Cypherpunk SEC Commissioner – Internewscast Journal
Morgan Stanley Files for Bitcoin and Solana ETFs With the SEC – FinanceFeeds
XRP Price Prediction As Price Slides Below $3, Shiba Inu News And Layer Brett’s 6,000% Staking Rewards

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Waterdrip Capital Releases Special Report: AI Computing Power and Bitcoin Are Reshaping Global Productivity and Value Systems
Next Article Bitcoin Price Prediction: $800M Short Squeeze Resets Market as BTC Holds $95K
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d