DeadLock ransomware uses Polygon smart contracts to evade tracking
Jan 15, 2026 23:39:54
According to monitoring by Group-IB, the ransomware family DeadLock is using Polygon smart contracts to distribute and rotate proxy server addresses to evade security detection.
This malware was first discovered in July 2025, embedding JS code that interacts with the Polygon network within HTML files, using an RPC list as a gateway to obtain server addresses controlled by the attacker. This technique is similar to the previously discovered EtherHiding, aiming to leverage decentralized ledgers to construct covert communication channels that are difficult to block. DeadLock currently has at least three variants, with the latest version also embedding the encrypted communication application Session to directly communicate with victims.
Related Projects
Latest News
ChainCatcher
1월 17, 2026 00:31:00
ChainCatcher
1월 17, 2026 00:17:46
ChainCatcher
1월 17, 2026 00:09:50
ChainCatcher
1월 17, 2026 00:03:30
ChainCatcher
1월 17, 2026 00:03:18












