HomeNewsDeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

DeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

-

Researchers at Group-IB reported on Thursday that a ransomware named DeadLock was first detected in July. DeadLock exploits Polygon smart contracts to rotate and distribute proxy addresses for its command-and-control infrastructure.

Code embedded in the malware calls a specific contract function to update proxy addresses dynamically. After encryption, infected systems receive a ransom note and a threat to sell stolen data if demands go unmet.

Storing proxy addresses on-chain removes a single point of failure and makes takedown difficult. Group-IB warned the method allows many variants and could be dangerous for organizations that do not take it seriously (Ed. note: on-chain records persist across distributed nodes indefinitely).

Weaponizing smart contracts is not new; a technique called “EtherHiding” has appeared previously. A North Korean actor identified as UNC5342 used this approach to embed JavaScript payloads in smart contracts, leveraging blockchain transactions to store and retrieve malicious code, and “This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.”

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Bitcoin Futures Open Interest Plummets Amidst Bearish Options, Jobs Data

Bitcoin's price struggles to hold above $72,000 as futures open interest falls to $34 billion, its lowest since November 2024. Data shows weak demand for...

Memecoin Trends May Signal Crypto Cycle Bottom & Bitcoin Rally Potential

The memecoin sector, valued at $29.51 billion, may serve as a leading indicator for broader cryptocurrency market trends. Analysis shows speculative memecoin rallies often precede...

SAND Tests Falling Wedge Support, Bullish Reversal Potential on Radar

The Sandbox (SAND) cryptocurrency is testing a critical technical pattern that analysts suggest could precede a significant price move. According to an analysis, SAND is...

Crypto PAC Spends $1.5M to Unseat Rep. Al Green in Texas Primary

The pro-crypto political action committee Protect Progress will spend $1.5 million to oppose Democratic Representative Al Green in Texas's upcoming primary election. The group, an...

Most Popular

spot_img