DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly – Turk Crypto News

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly – Turk Crypto News

Workforce-IB printed its file on Jan. 15 and stated the process may just make disruption tougher for defenders.
The malware reads on-chain knowledge, so sufferers don’t pay fuel charges.
Researchers stated Polygon isn’t inclined, however the tactic may just unfold.

Ransomware teams typically depend on command-and-control servers to control communications after breaking right into a gadget.

However safety researchers now say a low-profile pressure is the usage of blockchain infrastructure in some way that may be tougher to dam.

In a file printed on Jan. 15, cybersecurity company Workforce-IB stated a ransomware operation referred to as DeadLock is abusing Polygon (POL) sensible contracts to retailer and rotate proxy server addresses.

Those proxy servers are used to relay conversation between attackers and sufferers after techniques are inflamed.

Since the data sits on-chain and will also be up to date anytime, researchers warned that this manner may just make the gang’s backend extra resilient and harder to disrupt.

Sensible contracts used to retailer proxy data

Workforce-IB stated DeadLock does no longer rely on the standard setup of fastened command-and-control servers.

As a substitute, as soon as a gadget is compromised and encrypted, the ransomware queries a particular sensible contract deployed at the Polygon community.

That contract retail outlets the newest proxy deal with that DeadLock makes use of to be in contact. The proxy acts as a center layer, serving to attackers care for touch with out exposing their primary infrastructure immediately.

Because the sensible contract knowledge is publicly readable, the malware can retrieve the main points with out sending any blockchain transactions.

This additionally method sufferers don’t want to pay fuel charges or engage with wallets.

DeadLock best reads the tips, treating the blockchain as a continual supply of configuration knowledge.

Rotating infrastructure with out malware updates

One reason why this system stands proud is how briefly attackers can trade their conversation routes.

Workforce-IB stated the actors at the back of DeadLock can replace the proxy deal with saved within the contract every time vital.

That provides them the power to rotate infrastructure with out enhancing the ransomware itself or pushing new variations into the wild.

In conventional ransomware instances, defenders can infrequently block visitors via figuring out identified command-and-control servers.

However with an on-chain proxy listing, any proxy that will get flagged will also be changed just by updating the contract’s saved worth.

As soon as touch is established during the up to date proxy, sufferers obtain ransom calls for together with threats that stolen data shall be offered if fee isn’t made.

Why takedowns develop into harder

Workforce-IB warned that the usage of blockchain knowledge this fashion makes disruption considerably tougher.

There is not any unmarried central server that may be seized, got rid of, or close down.

Even supposing a particular proxy deal with is blocked, the attackers can transfer to some other one with no need to redeploy the malware.

Because the sensible contract stays out there thru Polygon’s dispensed nodes international, the configuration knowledge can live to tell the tale even supposing the infrastructure at the attackers’ aspect adjustments.

Researchers stated this provides ransomware operators a extra resilient command-and-control mechanism when put next with typical webhosting setups.

A small marketing campaign with a creative manner

DeadLock was once first noticed in July 2025 and has stayed reasonably low profile thus far.

Workforce-IB stated the operation has just a restricted choice of showed sufferers.

The file additionally famous that DeadLock isn’t connected to identified ransomware associate programmes and does no longer seem to function a public knowledge leak web page.

Whilst that can give an explanation for why the gang has won much less consideration than main ransomware manufacturers, researchers stated its technical manner merits shut tracking.

Workforce-IB warned that even supposing DeadLock stays small, its method may well be copied via extra established cybercriminal teams.

No Polygon vulnerability concerned

The researchers stressed out that DeadLock isn’t exploiting any vulnerability in Polygon itself.

Additionally it is no longer attacking third-party sensible contracts similar to decentralised finance protocols, wallets, or bridges.

As a substitute, the attackers are abusing the general public and immutable nature of blockchain knowledge to cover configuration data.

Workforce-IB when put next the solution to previous “EtherHiding” approaches, the place criminals used blockchain networks to distribute malicious configuration knowledge.

A number of sensible contracts hooked up to the marketing campaign have been deployed or up to date between August and Nov. 2025, in step with the company’s research.

Researchers stated the job stays restricted for now, however the concept that may well be reused in many alternative paperwork via different danger actors.

Whilst Polygon customers and builders don’t seem to be going through direct possibility from this explicit marketing campaign, Workforce-IB stated the case is some other reminder that public blockchains will also be misused to strengthen off-chain criminality in techniques which are tough to stumble on and dismantle.

Proportion this articleCategoriesTags

Website |  + posts
author avatar
spsingh