Saturday, March 7, 2026
No Result
View All Result
Blockchain 24hrs
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Blockchain Justice
  • Analysis
Crypto Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Blockchain Justice
  • Analysis
No Result
View All Result
Blockchain 24hrs
No Result
View All Result

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

Home Blockchain Justice
Share on FacebookShare on Twitter


Group-IB revealed its report on Jan. 15 and mentioned the tactic might make disruption tougher for defenders.
The malware reads on-chain knowledge, so victims don’t pay gasoline charges.
Researchers mentioned Polygon isn’t weak, however the tactic might unfold.

Ransomware teams normally depend on command-and-control servers to handle communications after breaking right into a system.

However safety researchers now say a low-profile pressure is utilizing blockchain infrastructure in a method that may very well be tougher to dam.

In a report revealed on Jan. 15, cybersecurity agency Group-IB mentioned a ransomware operation often known as DeadLock is abusing Polygon (POL) good contracts to retailer and rotate proxy server addresses.

These proxy servers are used to relay communication between attackers and victims after methods are contaminated.

As a result of the knowledge sits on-chain and might be up to date anytime, researchers warned that this method might make the group’s backend extra resilient and more durable to disrupt.

Good contracts used to retailer proxy data

Group-IB mentioned DeadLock doesn’t rely upon the same old setup of mounted command-and-control servers.

As a substitute, as soon as a machine is compromised and encrypted, the ransomware queries a particular good contract deployed on the Polygon community.

That contract shops the newest proxy deal with that DeadLock makes use of to speak. The proxy acts as a center layer, serving to attackers keep contact with out exposing their primary infrastructure immediately.

For the reason that good contract knowledge is publicly readable, the malware can retrieve the small print with out sending any blockchain transactions.

This additionally means victims don’t have to pay gasoline charges or work together with wallets.

DeadLock solely reads the knowledge, treating the blockchain as a persistent supply of configuration knowledge.

Rotating infrastructure with out malware updates

One motive this methodology stands out is how shortly attackers can change their communication routes.

Group-IB mentioned the actors behind DeadLock can replace the proxy deal with saved contained in the contract each time essential.

That offers them the flexibility to rotate infrastructure with out modifying the ransomware itself or pushing new variations into the wild.

In conventional ransomware instances, defenders can typically block site visitors by figuring out recognized command-and-control servers.

However with an on-chain proxy checklist, any proxy that will get flagged might be changed just by updating the contract’s saved worth.

As soon as contact is established via the up to date proxy, victims obtain ransom calls for together with threats that stolen data will probably be offered if cost isn’t made.

Why takedowns change into tougher

Group-IB warned that utilizing blockchain knowledge this manner makes disruption considerably tougher.

There isn’t any single central server that may be seized, eliminated, or shut down.

Even when a particular proxy deal with is blocked, the attackers can swap to a different one with out having to redeploy the malware.

For the reason that good contract stays accessible via Polygon’s distributed nodes worldwide, the configuration knowledge can live on even when the infrastructure on the attackers’ aspect modifications.

Researchers mentioned this provides ransomware operators a extra resilient command-and-control mechanism in contrast with typical internet hosting setups.

A small marketing campaign with an creative methodology

DeadLock was first noticed in July 2025 and has stayed comparatively low profile to date.

Group-IB mentioned the operation has solely a restricted variety of confirmed victims.

The report additionally famous that DeadLock isn’t linked to recognized ransomware affiliate programmes and doesn’t seem to function a public knowledge leak web site.

Whereas which will clarify why the group has acquired much less consideration than main ransomware manufacturers, researchers mentioned its technical method deserves shut monitoring.

Group-IB warned that even when DeadLock stays small, its approach may very well be copied by extra established cybercriminal teams.

No Polygon vulnerability concerned

The researchers harassed that DeadLock isn’t exploiting any vulnerability in Polygon itself.

Additionally it is not attacking third-party good contracts reminiscent of decentralised finance protocols, wallets, or bridges.

As a substitute, the attackers are abusing the general public and immutable nature of blockchain knowledge to cover configuration data.

Group-IB in contrast the approach to earlier “EtherHiding” approaches, the place criminals used blockchain networks to distribute malicious configuration knowledge.

A number of good contracts linked to the marketing campaign have been deployed or up to date between August and Nov. 2025, in line with the agency’s evaluation.

Researchers mentioned the exercise stays restricted for now, however the idea may very well be reused in many various types by different risk actors.

Whereas Polygon customers and builders are usually not going through direct threat from this particular marketing campaign, Group-IB mentioned the case is one other reminder that public blockchains might be misused to assist off-chain felony exercise in methods which can be tough to detect and dismantle.

Share this articleCategoriesTags



Source link

Tags: abusesBlockchainDeadlockPolygonproxyQuietlyransomwareRotateServers
Previous Post

BofA CEO Issues $6T Stablecoin Warning As Debate Heats Up

Next Post

Ethereum Treasury Bitmine Makes $200M Bet On MrBeast Firm

Related Posts

What the BPS ruling reveals about Australia’s crypto compliance gap
Regulations

What the BPS ruling reveals about Australia’s crypto compliance gap

January 28, 2026
Netherlands to tax unrealised Bitcoin gains under new Box 3 rules
Regulations

Netherlands to tax unrealised Bitcoin gains under new Box 3 rules

January 24, 2026
Vietnam launches formal licensing for digital asset trading platforms
Regulations

Vietnam launches formal licensing for digital asset trading platforms

January 26, 2026
Thailand moves toward crypto ETFs, futures and tokenised investment products
Regulations

Thailand moves toward crypto ETFs, futures and tokenised investment products

January 22, 2026
Portugal orders Polymarket to shut down over election betting surge
Regulations

Portugal orders Polymarket to shut down over election betting surge

January 30, 2026
South Korea may target fairer crypto market with banking rule changes: report
Regulations

South Korea may target fairer crypto market with banking rule changes: report

February 1, 2026
Next Post
Ethereum Treasury Bitmine Makes 0M Bet On MrBeast Firm

Ethereum Treasury Bitmine Makes $200M Bet On MrBeast Firm

Kaito winds down Yaps product after losing access to the X API

Kaito winds down Yaps product after losing access to the X API

Facebook Twitter Instagram Youtube RSS
Blockchain 24hrs

Blockchain 24hrs delivers the latest cryptocurrency and blockchain technology news, expert analysis, and market trends. Stay informed with round-the-clock updates and insights from the world of digital currencies.

CATEGORIES

  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Blockchain Justice
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Web3

SITEMAP

  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Blockchain 24hrs.
Blockchain 24hrs is not responsible for the content of external sites.

  • bitcoinBitcoin(BTC)$67,853.00-3.78%
  • ethereumEthereum(ETH)$1,973.40-4.68%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$626.95-2.77%
  • rippleXRP(XRP)$1.36-2.53%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$84.15-4.33%
  • tronTRON(TRX)$0.283881-0.87%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.05%
  • dogecoinDogecoin(DOGE)$0.090701-2.94%
No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoins
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Blockchain Justice
  • Analysis
Crypto Marketcap

Copyright © 2024 Blockchain 24hrs.
Blockchain 24hrs is not responsible for the content of external sites.