DeadLock ransomware uses Polygon smart contracts to evade tracking

Odaily Planet Daily reports that, according to Group-IB monitoring, the ransomware family DeadLock is using Polygon smart contracts to distribute and rotate proxy server addresses to evade security detection. The malware was first discovered in July 2025, embedding JS code in HTML files that interacts with the Polygon network, using RPC lists as gateways to obtain attacker-controlled server addresses. This technique is similar to the previously discovered EtherHiding, aiming to leverage decentralized ledgers to build covert communication channels that are difficult to block. DeadLock currently has at least three variants, with the latest version also embedding the encrypted communication app Session to communicate directly with victims.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments