Microsoft Threat Intelligence has published a technical breakdown of DeadLock, an emerging financially motivated ransomware operation distinguished by its use of decentralized infrastructure for victim communications and data leak operations.
DeadLock surfaced in July 2025 and runs a double-extortion playbook, encrypting victim systems while threatening to dump stolen data. By July 2026 the group’s leak blog listed over 80 victim organizations, more than half of them in Europe. Microsoft says it has seen DeadLock hit IT, mining, transport and logistics, manufacturing, hospitality, and consumer goods across Europe, Asia, the Americas, and Africa.
For recovery, the operation leans on the Session messaging network and blockchain-backed services holding and delivering resources across the extortion process. That setup probably hardens parts of its comms, leak-hosting, and negotiation stack, letting operators bounce back from disruption attempts while maintaining operations. Microsoft has seen multiple groups deploy DeadLock, among them affiliates of the Lynx and INC ransomware operations.
Written in Rust, the encryptor throttles itself based on available resources so systems stay responsive while files are encrypted. It also geo-fences by language and country, steering clear of former Soviet and Commonwealth of Independent States-linked environments and certain selected regions.
Microsoft’s write-up dissects the encryptor’s execution flow, evasion tricks, encryption design, and post-encryption behavior, including a decentralized recovery chat. The vendor also released indicators of compromise, Defender detections, and mitigation guidance for defenders.

