DeadLock Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
December 9, 2025
Last Seen
August 10, 2026

DeadLock is a ransomware family that is increasingly leveraging the BYOVD loader technique to load its payloads and bypass security controls.

Overview

DeadLock is a ransomware family that is increasingly leveraging the BYOVD loader technique to load its payloads and bypass security controls. By utilizing a loader that leverages a driver-based mechanism to execute code, DeadLock can disable endpoint detection and evade defenses, enhancing its stealth and operational impact.

Related Threat Clusters

  • Ransomware Tactics Evolve: EDR Killers Expand Beyond Vulnerable Drivers

    Recent research from ESET reveals that ransomware attackers are increasingly using EDR killers to disable endpoint detection and response (EDR) systems before launching their encryptors. These tools have become standard…

    18 articles · Updated March 19, 2026
  • DeadLock Ransomware Utilizes Decentralized Recovery Infrastructure

    DeadLock ransomware has emerged as a significant threat, employing a decentralized recovery chat that integrates the Polygon blockchain and the Session messenger. This ransomware utilizes a Rust-based encryptor that…

    2 articles · Updated August 10, 2026
  • Russian Access Broker Sentenced for $9M Ransomware Facilitation

    Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…

    21 articles · Updated March 24, 2026
  • DeadLock Ransomware Employs BYOVD Technique to Bypass Security

    DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response…

    3 articles · Updated December 10, 2025
  • DeadLock Ransomware Exploits Smart Contracts for Malicious Activities

    DeadLock is a ransomware family identified in July 2025, notable for its unique approach of utilizing Polygon smart contracts for proxy address storage. This method allows the ransomware to operate stealthily, impacting…

    9 articles · Updated January 15, 2026
  • DeadLock Ransomware Employs Blockchain for Evasion Tactics

    The DeadLock ransomware operation, first identified in July 2025, utilizes blockchain-based smart contracts to evade detection and manage proxy server addresses. This group has targeted various organizations while…

    9 articles · Updated January 14, 2026

Recent Intelligence Reports

  • DeadLock ransomware turns recovery chat into a decentralized takedown challenge — Feeds.4Sysops · August 10, 2026
  • DeadLock ransomware: Breaking down a Rust — Blogs.Microsoft · August 10, 2026
  • Russian Hacker Jailed for 81 Months Over $9M Ransomware Attacks — Decrypt.Co · March 24, 2026
  • EDR killers explained: Beyond the drivers — Welivesecurity · March 19, 2026
  • DeadLock Ransomware: Smart Contracts for Malicious Purposes — Cybersecurity-Review · January 15, 2026
  • DeadLock Ransomware: Smart Contracts for Malicious Purposes | Group — Group-Ib · January 15, 2026
  • DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation — Infosecurity-Magazine · January 14, 2026
  • DeadLock ransomware uses smart contracts to evade defenders — Theregister · January 14, 2026

CVSS v3.1 Breakdown