HomeNewsDeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

DeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

-

Researchers at Group-IB reported on Thursday that a ransomware named DeadLock was first detected in July. DeadLock exploits Polygon smart contracts to rotate and distribute proxy addresses for its command-and-control infrastructure.

Code embedded in the malware calls a specific contract function to update proxy addresses dynamically. After encryption, infected systems receive a ransom note and a threat to sell stolen data if demands go unmet.

Storing proxy addresses on-chain removes a single point of failure and makes takedown difficult. Group-IB warned the method allows many variants and could be dangerous for organizations that do not take it seriously (Ed. note: on-chain records persist across distributed nodes indefinitely).

Weaponizing smart contracts is not new; a technique called “EtherHiding” has appeared previously. A North Korean actor identified as UNC5342 used this approach to embed JavaScript payloads in smart contracts, leveraging blockchain transactions to store and retrieve malicious code, and “This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.”

LATEST POSTS

Anthropic in Last-Minute Talks With Pentagon to Avoid ‘Supply Chain Risk’ Label

Anthropic CEO Dario Amodei is in last-minute negotiations with the U.S. Department of Defense to secure continued Pentagon contracts and avoid a potential "supply chain...

Pi Network’s PI Token Jumps 13% as BTC Hits $74K, Ethereum Reclaims $2,100

Bitcoin surged to $74,000, its highest level in a month, as the market recovered from recent geopolitical volatility. Ethereum reclaimed $2,100, while the Pi Network's...

Dogecoin’s Glory Days Fade: Can the Meme Coin Regain Momentum?

Dogecoin, once a market darling driven by social media frenzy and celebrity endorsements, has seen its momentum collapse. From an all-time high near $0.73 in...

Bitcoin ETF Inflows Hit $462M Amid BTC’s Surge Past $73,000

US spot Bitcoin ETFs recorded $462 million in net inflows on Wednesday, marking a third consecutive day of positive flows and bringing the weekly total...

Most Popular

spot_img