HomeNewsDeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

DeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

-

Researchers at Group-IB reported on Thursday that a ransomware named DeadLock was first detected in July. DeadLock exploits Polygon smart contracts to rotate and distribute proxy addresses for its command-and-control infrastructure.

Code embedded in the malware calls a specific contract function to update proxy addresses dynamically. After encryption, infected systems receive a ransom note and a threat to sell stolen data if demands go unmet.

Storing proxy addresses on-chain removes a single point of failure and makes takedown difficult. Group-IB warned the method allows many variants and could be dangerous for organizations that do not take it seriously (Ed. note: on-chain records persist across distributed nodes indefinitely).

Weaponizing smart contracts is not new; a technique called “EtherHiding” has appeared previously. A North Korean actor identified as UNC5342 used this approach to embed JavaScript payloads in smart contracts, leveraging blockchain transactions to store and retrieve malicious code, and “This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.”

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Democrats add ethics, CFTC staffing amendments to crypto bill over Trump conflict concerns

US Democratic senators filed several amendments on Friday ahead of a Senate Agriculture Committee markup set for Tuesday, seeking clearer federal rules for digital assets...

SEC Dismisses Case Against Gemini After Crypto Investors Receive Full Restitution

The U.S. Securities and Exchange Commission has dismissed its lawsuit against Gemini Trust Company with prejudice, closing a major enforcement case related to the firm's...

OCC rebuffs Warren, will review World Liberty’s national trust charter amid Trump ties now

The OCC refused Senator Elizabeth Warren's request to pause World Liberty Financial's charter review. She sought the pause until President Donald Trump divested, citing founder...

Chainlink Bridges $80T in US Equities On-Chain as Network Reserves, Interest Surge

Chainlink has expanded its blockchain infrastructure by introducing real-time U.S. stock and ETF prices on-chain, a move the firm claims unlocks $80 trillion in equities...

Most Popular

spot_img