DeadLock is a ransomware family that is increasingly leveraging the BYOVD loader technique to load its payloads and bypass security controls.
DeadLock is a ransomware family that is increasingly leveraging the BYOVD loader technique to load its payloads and bypass security controls. By utilizing a loader that leverages a driver-based mechanism to execute code, DeadLock can disable endpoint detection and evade defenses, enhancing its stealth and operational impact.
Recent research from ESET reveals that ransomware attackers are increasingly using EDR killers to disable endpoint detection and response (EDR) systems before launching their encryptors. These tools have become standard…
DeadLock ransomware has emerged as a significant threat, employing a decentralized recovery chat that integrates the Polygon blockchain and the Session messenger. This ransomware utilizes a Rust-based encryptor that…
Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response…
DeadLock is a ransomware family identified in July 2025, notable for its unique approach of utilizing Polygon smart contracts for proxy address storage. This method allows the ransomware to operate stealthily, impacting…
The DeadLock ransomware operation, first identified in July 2025, utilizes blockchain-based smart contracts to evade detection and manage proxy server addresses. This group has targeted various organizations while…