HomeNewsDeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

DeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

-

Researchers at Group-IB reported on Thursday that a ransomware named DeadLock was first detected in July. DeadLock exploits Polygon smart contracts to rotate and distribute proxy addresses for its command-and-control infrastructure.

Code embedded in the malware calls a specific contract function to update proxy addresses dynamically. After encryption, infected systems receive a ransom note and a threat to sell stolen data if demands go unmet.

Storing proxy addresses on-chain removes a single point of failure and makes takedown difficult. Group-IB warned the method allows many variants and could be dangerous for organizations that do not take it seriously (Ed. note: on-chain records persist across distributed nodes indefinitely).

Weaponizing smart contracts is not new; a technique called “EtherHiding” has appeared previously. A North Korean actor identified as UNC5342 used this approach to embed JavaScript payloads in smart contracts, leveraging blockchain transactions to store and retrieve malicious code, and “This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.”

LATEST POSTS

Poland President Vetos Second MiCA Crypto Bill as 2026 Deadline Approaches

Poland's president has vetoed a second legislative attempt to implement the EU's landmark Markets in Crypto-Assets Regulation (MiCA), creating regulatory uncertainty for local platforms. The...

Bitcoin vs AI: New Data Shows True Culprit Behind Rising US Power Bills

Across the United States, rising electricity bills are sparking protests against new data centers. Politicians are proposing new rules on energy-intensive industries, but a report...

Ethereum RWAs Pass $15B as Liquid Staking ETP Launches in Europe

The market for Ethereum-based real-world assets (RWAs) has surpassed $15 billion in total market capitalization, a nearly 200% increase from the previous year. Separately, WisdomTree...

Shiba Inu’s 2026 reality check: Shibarium struggles and token burn leave prospects unclear

According to CoinGecko, SHIB trades near $0.0000065, down over 92% from its 2021 peak, and on-chain metrics in early 2026 have renewed debate about the...

Most Popular

spot_img