Hiring: Business Development, Join us! 【View Details】
API Download the RootData App

DeadLock ransomware uses Polygon smart contracts to evade tracking

1月 15, 2026 23:39:54

Share to

According to monitoring by Group-IB, the ransomware family DeadLock is using Polygon smart contracts to distribute and rotate proxy server addresses to evade security detection.

This malware was first discovered in July 2025, embedding JS code that interacts with the Polygon network within HTML files, using an RPC list as a gateway to obtain server addresses controlled by the attacker. This technique is similar to the previously discovered EtherHiding, aiming to leverage decentralized ledgers to construct covert communication channels that are difficult to block. DeadLock currently has at least three variants, with the latest version also embedding the encrypted communication application Session to directly communicate with victims.

Recent Fundraising

More
-- 3월 10
$80M 3월 9

New Tokens

More
3월 8
3월 4
2월 27

Latest Updates on 𝕏

More
3월 9
Hasu Followed Dune
3월 9