Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-10 and was added to the RWP archive on 2026-09-07.
DeadLock's encryptor is Rust; the negotiation desk is a Polygon contract and an HTML chat
Microsoft — 80-plus leak-site names by July 2026, Lynx/INC affiliates among deployers, XChaCha20 per file, Session + Wasabi + smart contracts so takedowns do not kill the recovery channel.
Bottom line up front
CONFIRMED Microsoft 10 August 2026 — DeadLock is financially motivated, first seen July 2025, double extortion. Deployed by multiple groups including a Lynx/INC affiliate. Leak site ("DeadLock blog") more than 80 claimed orgs by July 2026, over half in Europe; sectors IT, mining, transport, manufacturing, hospitality, consumer goods, multi-continent. Encryptor: Rust, resource-aware (can keep the desktop responsive), per-file XChaCha20, no practical decrypt without operator key. Recovery ecosystem: Session messenger, Wasabi object storage, Polygon contracts holding proxy URLs and blog content, HTML note RECOVERY_CHAT.<UID>.html as a self-contained chat/leak browser. THN: 96 claimed in their recap; ZeroFox June flash already saw ~80 listings and warned claims were thinly evidenced. .dlock extension. OT process impact: UNKNOWN in these sources.
Historical backfill of 10 August 2026 reporting; added 7 September 2026.
What happened
Ransomware learned from bulletproof-hosting seizures: put the helpdesk on a chain. CPU-throttled encryption removes the "machine is on fire" tell.
Why it mattered
Seizing a leak domain does not seize a contract. IR that waits for the desktop to freeze will encrypt in the background.
Who / what was affected
Microsoft-named sectors/regions. Leak-site names are claims until matched to IR.
Technical context
Hunt .dlock, RECOVERY_CHAT HTML, Rust encryptors pausing on CPU, outbound to Session/Wasabi. Isolate on suspicion even if the UI is snappy.
Exploitation / threat status at the time
CONFIRMED Microsoft malware/infra analysis.
REPORTED victim counts via leak sites (quality varies).
What defenders should have done
- Offline backups; no decryptor as of the reporting.
- Do not open the HTML chat on a production net.
- Watch Lynx/INC affiliate tooling as a leading indicator.
RWP assessment
Confidence: High on the encryptor/infra. Leak-site math is REPORTED.
Defensive actions
- Canaries for .dlock.
- EDR for quiet high-volume file rewrite.
- Legal: leak-site names are not proof of your breach.
Sources
- Microsoft Threat Intelligence — DeadLock ransomware
- The Hacker News — DeadLock uses Polygon smart contracts
- ZeroFox — DeadLock leak site lists over 80 victims