Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-10 and was added to the RWP archive on 2026-09-07.

Daily Top · Ransomware

DeadLock's encryptor is Rust; the negotiation desk is a Polygon contract and an HTML chat

Microsoft — 80-plus leak-site names by July 2026, Lynx/INC affiliates among deployers, XChaCha20 per file, Session + Wasabi + smart contracts so takedowns do not kill the recovery channel.

RWP Ventures · 2026-09-07 · event 2026-08-10 · 1 min read · priority 8.4

Bottom line up front

CONFIRMED Microsoft 10 August 2026 — DeadLock is financially motivated, first seen July 2025, double extortion. Deployed by multiple groups including a Lynx/INC affiliate. Leak site ("DeadLock blog") more than 80 claimed orgs by July 2026, over half in Europe; sectors IT, mining, transport, manufacturing, hospitality, consumer goods, multi-continent. Encryptor: Rust, resource-aware (can keep the desktop responsive), per-file XChaCha20, no practical decrypt without operator key. Recovery ecosystem: Session messenger, Wasabi object storage, Polygon contracts holding proxy URLs and blog content, HTML note RECOVERY_CHAT.<UID>.html as a self-contained chat/leak browser. THN: 96 claimed in their recap; ZeroFox June flash already saw ~80 listings and warned claims were thinly evidenced. .dlock extension. OT process impact: UNKNOWN in these sources.

Historical backfill of 10 August 2026 reporting; added 7 September 2026.

What happened

Ransomware learned from bulletproof-hosting seizures: put the helpdesk on a chain. CPU-throttled encryption removes the "machine is on fire" tell.

Why it mattered

Seizing a leak domain does not seize a contract. IR that waits for the desktop to freeze will encrypt in the background.

Who / what was affected

Microsoft-named sectors/regions. Leak-site names are claims until matched to IR.

Technical context

Hunt .dlock, RECOVERY_CHAT HTML, Rust encryptors pausing on CPU, outbound to Session/Wasabi. Isolate on suspicion even if the UI is snappy.

Exploitation / threat status at the time

CONFIRMED Microsoft malware/infra analysis.

REPORTED victim counts via leak sites (quality varies).

What defenders should have done

  1. Offline backups; no decryptor as of the reporting.
  2. Do not open the HTML chat on a production net.
  3. Watch Lynx/INC affiliate tooling as a leading indicator.

RWP assessment

Confidence: High on the encryptor/infra. Leak-site math is REPORTED.

Defensive actions

  1. Canaries for .dlock.
  2. EDR for quiet high-volume file rewrite.
  3. Legal: leak-site names are not proof of your breach.

Sources

  1. Microsoft Threat Intelligence — DeadLock ransomware
  2. The Hacker News — DeadLock uses Polygon smart contracts
  3. ZeroFox — DeadLock leak site lists over 80 victims