BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up
HomeNewsDeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

DeadLock ransomware uses Polygon smart contracts rotate proxy C2 addresses, warns Group-IB

-

Researchers at Group-IB reported on Thursday that a ransomware named DeadLock was first detected in July. DeadLock exploits Polygon smart contracts to rotate and distribute proxy addresses for its command-and-control infrastructure.

Code embedded in the malware calls a specific contract function to update proxy addresses dynamically. After encryption, infected systems receive a ransom note and a threat to sell stolen data if demands go unmet.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Storing proxy addresses on-chain removes a single point of failure and makes takedown difficult. Group-IB warned the method allows many variants and could be dangerous for organizations that do not take it seriously (Ed. note: on-chain records persist across distributed nodes indefinitely).

Weaponizing smart contracts is not new; a technique called “EtherHiding” has appeared previously. A North Korean actor identified as UNC5342 used this approach to embed JavaScript payloads in smart contracts, leveraging blockchain transactions to store and retrieve malicious code, and “This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.”

Most Popular

Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount