DeadLock ransomware uses Polygon smart contracts to evade tracking

robot
Abstract generation in progress

Mars Finance News, according to Group-IB monitoring, the ransomware family DeadLock is utilizing Polygon smart contracts to distribute and rotate proxy server addresses in order to evade security detection. The malware was first discovered in July 2025, embedding JS code that interacts with the Polygon network within HTML files, using RPC lists as gateways to obtain attacker-controlled server addresses. This technique is similar to the previously discovered EtherHiding, aiming to leverage decentralized ledgers to build covert communication channels that are difficult to block. DeadLock currently has at least three variants, with the latest version also embedding the encrypted communication app Session to directly communicate with victims.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)