Blockchain
DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly – Crypto News
- Group-IB published its report on Jan. 15 and said the method could make disruption harder for defenders.
- The malware reads on-chain data, so victims do not pay gas fees.
- Researchers said Polygon is not vulnerable, but the tactic could spread.
Ransomware groups usually rely on command-and-control servers to manage communications after breaking into a system.
But security researchers now say a low-profile strain is using blockchain infrastructure in a way that could be harder to block.
In a report published on Jan. 15, cybersecurity firm Group-IB said a ransomware operation known as DeadLock is abusing Polygon (POL) smart contracts to store and rotate proxy server addresses.
These proxy servers are used to relay communication between attackers and victims after systems are infected.
Because the information sits on-chain and can be updated anytime, researchers warned that this approach could make the group’s backend more resilient and tougher to disrupt.
Smart contracts used to store proxy information
Group-IB said DeadLock does not depend on the usual setup of fixed command-and-control servers.
Instead, once a machine is compromised and encrypted, the ransomware queries a specific smart contract deployed on the Polygon network.
That contract stores the latest proxy address that DeadLock uses to communicate. The proxy acts as a middle layer, helping attackers maintain contact without exposing their main infrastructure directly.
Since the smart contract data is publicly readable, the malware can retrieve the details without sending any blockchain transactions.
This also means victims do not need to pay gas fees or interact with wallets.
DeadLock only reads the information, treating the blockchain as a persistent source of configuration data.
Rotating infrastructure without malware updates
One reason this method stands out is how quickly attackers can change their communication routes.
Group-IB said the actors behind DeadLock can update the proxy address stored inside the contract whenever necessary.
That gives them the ability to rotate infrastructure without modifying the ransomware itself or pushing new versions into the wild.
In traditional ransomware cases, defenders can sometimes block traffic by identifying known command-and-control servers.
But with an on-chain proxy list, any proxy that gets flagged can be replaced simply by updating the contract’s stored value.
Once contact is established through the updated proxy, victims receive ransom demands along with threats that stolen information will be sold if payment is not made.
Why takedowns become more difficult
Group-IB warned that using blockchain data this way makes disruption significantly harder.
There is no single central server that can be seized, removed, or shut down.
Even if a specific proxy address is blocked, the attackers can switch to another one without having to redeploy the malware.
Since the smart contract remains accessible through Polygon’s distributed nodes worldwide, the configuration data can continue to exist even if the infrastructure on the attackers’ side changes.
Researchers said this gives ransomware operators a more resilient command-and-control mechanism compared with conventional hosting setups.
A small campaign with an inventive method
DeadLock was first observed in July 2025 and has stayed relatively low profile so far.
Group-IB said the operation has only a limited number of confirmed victims.
The report also noted that DeadLock is not linked to known ransomware affiliate programmes and does not appear to operate a public data leak site.
While that may explain why the group has received less attention than major ransomware brands, researchers said its technical approach deserves close monitoring.
Group-IB warned that even if DeadLock remains small, its technique could be copied by more established cybercriminal groups.
No Polygon vulnerability involved
The researchers stressed that DeadLock is not exploiting any vulnerability in Polygon itself.
It is also not attacking third-party smart contracts such as decentralised finance protocols, wallets, or bridges.
Instead, the attackers are abusing the public and immutable nature of blockchain data to hide configuration information.
Group-IB compared the technique to earlier “EtherHiding” approaches, where criminals used blockchain networks to distribute malicious configuration data.
Several smart contracts connected to the campaign were deployed or updated between August and Nov. 2025, according to the firm’s analysis.
Researchers said the activity remains limited for now, but the concept could be reused in many different forms by other threat actors.
While Polygon users and developers are not facing direct risk from this specific campaign, Group-IB said the case is another reminder that public blockchains can be misused to support off-chain criminal activity in ways that are difficult to detect and dismantle.
-
Blockchain6 days agoDubai DIFC Shifts Crypto Token Vetting to Licensed Firms – Crypto News
-
Blockchain6 days agoDubai DIFC Shifts Crypto Token Vetting to Licensed Firms – Crypto News
-
Blockchain7 days agoCrypto YouTube Views Crash To 2021 Lows Amid Bear Sentiment – Crypto News
-
Blockchain1 week agoBitcoin Compresses Below $94K, Possible Repeat Of ’25 Breakout Looms – Crypto News
-
Blockchain1 week agoBitcoin Compresses Below $94K, Possible Repeat Of ’25 Breakout Looms – Crypto News
-
others3 days ago
Breaking: U.S. Jobless Claims Signal Labor Market Rebound as Fed Set to Hold Rates at January FOMC – Crypto News
-
Blockchain1 week agoBitcoin Network Mining Difficulty Falls in Jan 2026 – Crypto News
-
others7 days ago
Will Bipartisan Votes Pass the CLARITY Act on January 15 As Key Lawmaker Buys Bitcoin – Crypto News
-
Blockchain1 week agoHere’s Why $99K Might Be The Next Crucial Level To Watch – Crypto News
-
Blockchain1 week agoBitcoin Range-Bound Into The Weekend, But Next Week Holds The Real Test – Crypto News
-
Blockchain6 days agoBlockchain Regulatory Clarity Paves the Way for Adoption – Crypto News
-
others3 days agoXAU/USD returns above $4,600 as the Dollar hesitates – Crypto News
-
Technology1 week agoCES Day 3 2026 wrap: From a lollipop that plays music to Project Ava & more – Crypto News
-
Blockchain1 week agoRussians Ask if Pensions Can Be Paid in Crypto as Adoption Rises – Crypto News
-
Cryptocurrency1 week agoNVDA Takes On Competition and Export Policy – Crypto News
-
others7 days ago
Top 5 Cryptocurrency Events To Watch This Week: Bullish Run Ahead? – Crypto News
-
others7 days ago
Top 5 Cryptocurrency Events To Watch This Week: Bullish Run Ahead? – Crypto News
-
others7 days agoAustralian Dollar gains on cautious tone surrounding RBA outlook – Crypto News
-
Blockchain5 days agoFormer NYC mayor backed token tumbles on Solana amid liquidity fears – Crypto News
-
Technology5 days agoTech companies must address impact on natural resources, failure threatens firms long term resilience: WEF – Crypto News
-
Technology4 days agoGoogle adds vertical video support to Veo 3.1 for shorts and reels: How it works – Crypto News
-
Technology4 days agoSamsung Galaxy S26 could finally match Plus and Ultra models in charging speed: Report – Crypto News
-
Metaverse1 week agoElon Musk’s Grok restricts image-making tool for X users after global backlash over obscene AI images – Crypto News
-
Blockchain1 week agoBNY Enables Tokenized Deposits for Banks, Digital-Native Firms – Crypto News
-
Blockchain1 week ago17 Years On and Hal Finney’s ‘Running Bitcoin’ Post Is Still Celebrated – Crypto News
-
Technology1 week agoiPhone Air 2 could fix two of the biggest issues with iPhone Air: here’s what we know – Crypto News
-
Technology1 week agoDid you receive a mail to reset Instagram password? Is it a data breach? Is it a 2022 claim going viral? Meta responds – Crypto News
-
Business1 week ago
Crypto Price Prediction Ahead of US CPI Inflation Data- ETH, ADA, Pi Coin – Crypto News
-
Business7 days ago
Dogecoin ETF by 21Shares Gains Approval to Launch This Week – Crypto News
-
Blockchain7 days agoCZ Fuels Optimism As Binance Coin’s $1,000 Target Trends – Crypto News
-
Blockchain5 days agoWhat NFT Paris Cancellation Reveals About the NFT Market in 2026 – Crypto News
-
others5 days ago
Standard Chartered Predicts Ethereum Price could reach $40,000 by 2030 – Crypto News
-
Technology5 days ago
Bitcoin Price Reclaims $96K as Bitwise CIO Predicts “Parabolic” Run From BTC ETF Flows – Crypto News
-
others4 days ago
Top 3 Meme Coins Price Prediction: PEPE, Dogecoin, and Shiba Inu as 8% Market Boost Fuels Growth – Crypto News
-
Technology4 days ago
MSTR Stock Rises as Bitcoin Hits New 2026 High; Expert Predicts $455 Target – Crypto News
-
Technology4 days agoVerizon outage disrupts calling and data services for wireless customers across the US – Crypto News
-
Business1 week ago
Breaking: South Korea Confirms Spot Bitcoin ETF Launch in 2026 – Crypto News
-
Technology1 week agoGermany plans measures to combat harmful AI image manipulation – Crypto News
-
Technology1 week agoGermany plans measures to combat harmful AI image manipulation – Crypto News
-
Technology1 week agoBrew, smell, and serve: AI steals the show at CES 2026 – Crypto News
-
Cryptocurrency1 week agoWill Rolls Royce Go Below 1,000p Before The Year Ends? – Crypto News
-
Blockchain1 week agoKinexys by J.P. Morgan to Integrate Token With Canton Blockchain – Crypto News
-
Technology1 week ago
Stock Market Today Jan 9: Why Gold, S&P 500, and Nasdaq Prices are Surging? – Crypto News
-
Business1 week ago
Crypto Platforms Polymarket and Kalshi Hit With Cease-and-Desist Orders in Tennessee – Crypto News
-
Business1 week ago
Best Solana DEXs for Investors and Traders in 2026 – Top 7 Reviewed – Crypto News
-
Business1 week ago
Crypto Price Prediction Ahead of US CPI Inflation Data- ETH, ADA, Pi Coin – Crypto News
-
Business1 week ago
Crypto Price Prediction Ahead of US CPI Inflation Data- ETH, ADA, Pi Coin – Crypto News
-
Business1 week ago
Michael Saylor Posts “Big Orange” — Is Another Massive BTC Purchase Coming Tomorrow? – Crypto News
-
Business1 week ago
Tether At Center Stage in US Venezuela Conflict As 80% Oil Revenue Stays in Stablecoin – Crypto News
-
others7 days ago
Top 5 Cryptocurrency Events To Watch This Week: Bullish Run Ahead? – Crypto News
