Wednesday, January 21, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Alt Coins Polygon

DeadLock ransomware group exploit Polygon smart contracts for stealth

cryptonews100_tggfrn by cryptonews100_tggfrn
January 16, 2026
in Polygon
0
DeadLock ransomware group exploit Polygon smart contracts for stealth
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


DeadLock, a ransomware group that first emerged in July 2025, has made information once more, and this time it’s for abusing Polygon blockchain smart contracts to handle and rotate proxy server addresses, in accordance with analysis revealed by cybersecurity agency Group-IB. 

The ransomware operation makes use of blockchain-based smart contracts to retailer the group’s proxy server URL, permitting frequent rotation that makes it tough for defenders to completely block infrastructure.

Related articles

Everclear introduces cross-chain asset settlement for the Mantle Ecosystem

Everclear introduces cross-chain asset settlement for the Mantle Ecosystem

January 21, 2026
Zero Knowledge Proof Set To Crush Polygon And Avalanche, Targeting 7000x Gains In Crypto Market 2026

Zero Knowledge Proof Set To Crush Polygon And Avalanche, Targeting 7000x Gains In Crypto Market 2026

January 20, 2026

After encrypting a sufferer’s programs, DeadLock drops an HTML file that acts as a wrapper for the decentralized messaging platform, Session.

How does the DeadLock ransomware work on Polygon?

Embedded JavaScript code inside the file queries a selected Polygon smart contract to acquire the present proxy URL, which then relays encrypted messages between the sufferer and the attacker’s Session ID.

These read-only blockchain calls generate no transactions or charges, making them cost-free for the attackers to keep up.

Group-IB researchers famous that the exploit of smart contracts to ship proxy addresses is an attention-grabbing technique the place attackers can apply infinite variants of this method, with creativeness being the one restrict.

The method isn’t nicely documented and under-reported however its utilization is steadily gaining traction within the wild, in accordance with safety researchers.

Investigation by Cisco Talos revealed that DeadLock positive aspects preliminary entry by exploiting CVE-2024-51324, a Baidu Antivirus vulnerability, utilizing a way often known as “bringing your personal susceptible driver” to terminate endpoint detection and response processes.

DeadLock comes up with new extortion ways

DeadLock is totally different from most ransomware operations as a result of it abandons the standard double extortion method and doesn’t have a knowledge leak web site the place it might publicize assaults.

As a substitute, the group threatens to promote stolen knowledge on underground markets whereas providing victims safety reviews and guarantees to not re-target them if ransom is paid.

Group-IB’s infrastructure monitoring has not drawn any threads between DeadLock and any recognized ransomware affiliate packages. The truth is, the group maintains a comparatively low profile. Nevertheless, they discovered smart contract copies that had been first created and up to date in August 2025 and later up to date in November 2025.

Group-IB said that it efficiently “tracked its infrastructure by blockchain transactions, revealing funding patterns and lively servers.”

Nation-state actors undertake comparable methods

Google Threat Intelligence Group noticed North Korean risk actor UNC5342 utilizing a associated method referred to as EtherHiding to ship malware and facilitate cryptocurrency theft since February 2025.

Based on Google, “EtherHiding entails embedding malicious code, usually within the type of JavaScript payloads, inside a smart contract on a public blockchain like BNB Smart Chain or Ethereum.”

Polygon occurs to be a layer-2 blockchain that’s constructed on Ethereum’s layer-1 infrastructure.

Whereas DeadLock stays low quantity and low affect, safety researchers warn that it applies modern strategies showcasing a ability set that may grow to be harmful if organizations don’t take the risk it poses critically.

Aside from calling on companies to be proactive in detecting malware, Group-IB advisable that they need to add extra layers of safety, equivalent to multifactor authentication and credential-based options.

The cybersecurity agency additionally said that companies ought to have a knowledge backup, prepare their workers, patch up vulnerabilities, and, very importantly, “by no means pay the ransom” however contact incident response consultants as rapidly as attainable in the event that they ever get attacked.

For those who’re studying this, you’re already forward. Stay there with our newsletter.



Source link

Tags: contractsDeadlockexploitGroupPOLYGONransomwareSmartStealth
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Everclear introduces cross-chain asset settlement for the Mantle Ecosystem

Everclear introduces cross-chain asset settlement for the Mantle Ecosystem

by cryptonews100_tggfrn
January 21, 2026
0

Disclosure: This text doesn't symbolize funding recommendation. The content material and supplies featured on this web page are for academic...

Zero Knowledge Proof Set To Crush Polygon And Avalanche, Targeting 7000x Gains In Crypto Market 2026

Zero Knowledge Proof Set To Crush Polygon And Avalanche, Targeting 7000x Gains In Crypto Market 2026

by cryptonews100_tggfrn
January 20, 2026
0

The worldwide cryptocurrency market at the moment hovers round $3.22 trillion, exhibiting cautious exercise from institutional traders. Whereas Polygon value...

NYSE Builds Tokenized Securities Platform for 24/7 Stock Trading

NYSE Builds Tokenized Securities Platform for 24/7 Stock Trading

by cryptonews100_tggfrn
January 20, 2026
0

The New York Stock Trade is moving into the way forward for finance with a brand new platform designed for...

Why ZKP Crypto Could See Major Gains While Avalanche & Polygon Price Stay Flat in 2026

Why ZKP Crypto Could See Major Gains While Avalanche & Polygon Price Stay Flat in 2026

by cryptonews100_tggfrn
January 20, 2026
0

The worldwide cryptocurrency market sits close to a $3.22 trillion valuation, displaying a cautious however regular temper amongst institutional and...

INDODAX Market Signal 19 Januari 2026

INDODAX Market Signal 19 Januari 2026

by cryptonews100_tggfrn
January 20, 2026
0

This week, the bullish crypto lineup is led by World Liberty Monetary (WLFI) in first place, adopted by Polygon Ecosystem Token...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

River and Sui Announce Strategic Partnership to Expand Multi-Chain Capital into Sui Ecosystem

January 21, 2026
Canada Warns That Trump’s America Is Causing “Rupture” in World Order

Canada Warns That Trump’s America Is Causing “Rupture” in World Order

January 21, 2026
U.S. stock market opens with crypto sector performing weakly, Strategy (MSTR) down 1.08%

U.S. stock market closed with three major indices plummeting, crypto sector plunges, Strategy (MSTR) down 7.76%

January 21, 2026

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (266) Altcoins (169) Bitcoin (1261) BTC (315) Buy (394) Cardano (534) ChainLink (386) crypto (1605) Cryptocurrency (510) DOGE (227) Dogecoin (541) DOT (189) ETF (333) ETFs (175) ETH (304) Ethereum (741) eyes (179) Heres (171) Inu (378) investors (176) Launch (170) launches (171) Link (174) market (520) million (196) News (663) Polkadot (280) POLYGON (228) prediction (382) Presale (269) price (1167) rally (253) RWA (246) SHIB (184) Shiba (390) Solana (637) Stablecoin (172) Sui (387) today (169) token (183) top (338) TradingView (254) Trump (213) world (172) XRP (904)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Litecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.