Sunday, February 8, 2026
No Result
View All Result
Coins League
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
No Result
View All Result
Coins League
No Result
View All Result

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

January 18, 2026
in Scam Alert
Reading Time: 4 mins read
0 0
A A
0
Home Scam Alert
Share on FacebookShare on TwitterShare on E Mail


Group-IB revealed its report on Jan. 15 and mentioned the strategy might make disruption more durable for defenders.
The malware reads on-chain knowledge, so victims don’t pay gasoline charges.
Researchers mentioned Polygon will not be susceptible, however the tactic might unfold.

Ransomware teams normally depend on command-and-control servers to handle communications after breaking right into a system.

However safety researchers now say a low-profile pressure is utilizing blockchain infrastructure in a manner that could possibly be more durable to dam.

In a report revealed on Jan. 15, cybersecurity agency Group-IB mentioned a ransomware operation generally known as DeadLock is abusing Polygon (POL) sensible contracts to retailer and rotate proxy server addresses.

These proxy servers are used to relay communication between attackers and victims after techniques are contaminated.

As a result of the data sits on-chain and will be up to date anytime, researchers warned that this method might make the group’s backend extra resilient and harder to disrupt.

Good contracts used to retailer proxy info

Group-IB mentioned DeadLock doesn’t rely on the same old setup of fastened command-and-control servers.

As an alternative, as soon as a machine is compromised and encrypted, the ransomware queries a selected sensible contract deployed on the Polygon community.

That contract shops the newest proxy tackle that DeadLock makes use of to speak. The proxy acts as a center layer, serving to attackers preserve contact with out exposing their foremost infrastructure straight.

For the reason that sensible contract knowledge is publicly readable, the malware can retrieve the small print with out sending any blockchain transactions.

This additionally means victims don’t must pay gasoline charges or work together with wallets.

DeadLock solely reads the data, treating the blockchain as a persistent supply of configuration knowledge.

Rotating infrastructure with out malware updates

One cause this methodology stands out is how rapidly attackers can change their communication routes.

Group-IB mentioned the actors behind DeadLock can replace the proxy tackle saved contained in the contract every time obligatory.

That offers them the power to rotate infrastructure with out modifying the ransomware itself or pushing new variations into the wild.

In conventional ransomware instances, defenders can generally block site visitors by figuring out identified command-and-control servers.

However with an on-chain proxy checklist, any proxy that will get flagged will be changed just by updating the contract’s saved worth.

As soon as contact is established by the up to date proxy, victims obtain ransom calls for together with threats that stolen info will likely be offered if cost will not be made.

Why takedowns turn out to be tougher

Group-IB warned that utilizing blockchain knowledge this fashion makes disruption considerably more durable.

There is no such thing as a single central server that may be seized, eliminated, or shut down.

Even when a selected proxy tackle is blocked, the attackers can swap to a different one with out having to redeploy the malware.

For the reason that sensible contract stays accessible by Polygon’s distributed nodes worldwide, the configuration knowledge can live on even when the infrastructure on the attackers’ facet adjustments.

Researchers mentioned this provides ransomware operators a extra resilient command-and-control mechanism in contrast with typical internet hosting setups.

A small marketing campaign with an creative methodology

DeadLock was first noticed in July 2025 and has stayed comparatively low profile thus far.

Group-IB mentioned the operation has solely a restricted variety of confirmed victims.

The report additionally famous that DeadLock will not be linked to identified ransomware affiliate programmes and doesn’t seem to function a public knowledge leak website.

Whereas which will clarify why the group has acquired much less consideration than main ransomware manufacturers, researchers mentioned its technical method deserves shut monitoring.

Group-IB warned that even when DeadLock stays small, its approach could possibly be copied by extra established cybercriminal teams.

No Polygon vulnerability concerned

The researchers careworn that DeadLock will not be exploiting any vulnerability in Polygon itself.

It’s also not attacking third-party sensible contracts corresponding to decentralised finance protocols, wallets, or bridges.

As an alternative, the attackers are abusing the general public and immutable nature of blockchain knowledge to cover configuration info.

Group-IB in contrast the approach to earlier “EtherHiding” approaches, the place criminals used blockchain networks to distribute malicious configuration knowledge.

A number of sensible contracts related to the marketing campaign had been deployed or up to date between August and Nov. 2025, in accordance with the agency’s evaluation.

Researchers mentioned the exercise stays restricted for now, however the idea could possibly be reused in many various types by different menace actors.

Whereas Polygon customers and builders usually are not going through direct danger from this particular marketing campaign, Group-IB mentioned the case is one other reminder that public blockchains will be misused to help off-chain prison exercise in methods which can be troublesome to detect and dismantle.

Share this articleCategoriesTags



Source link

Tags: abusesBlockchainDeadlockPolygonproxyQuietlyransomwareRotateServers
Previous Post

KBC to Offer Regulated Crypto Trading in Belgium

Next Post

Ethereum Treasury Bitmine Makes $200M Bet On MrBeast Firm

Related Posts

MakinaFi hit by $4.1M Ethereum hack as MEV tactics suspected
Scam Alert

MakinaFi hit by $4.1M Ethereum hack as MEV tactics suspected

January 20, 2026
Tether freezes $182M in USDT, highlighting centralized control in stablecoins
Scam Alert

Tether freezes $182M in USDT, highlighting centralized control in stablecoins

January 12, 2026
How global sanctions are reshaping illicit crypto activity
Scam Alert

How global sanctions are reshaping illicit crypto activity

January 10, 2026
Truebit protocol hack exposes DeFi security risks as TRU token collapses
Scam Alert

Truebit protocol hack exposes DeFi security risks as TRU token collapses

January 14, 2026
Fake MetaMask 2FA phishing scam uses polished design to steal wallet seed phrases
Scam Alert

Fake MetaMask 2FA phishing scam uses polished design to steal wallet seed phrases

January 6, 2026
Silent wallet drains raise fresh crypto security concerns across EVM networks
Scam Alert

Silent wallet drains raise fresh crypto security concerns across EVM networks

January 2, 2026
Next Post
Ethereum Treasury Bitmine Makes $200M Bet On MrBeast Firm

Ethereum Treasury Bitmine Makes $200M Bet On MrBeast Firm

Kaito winds down Yaps product after losing access to the X API

Kaito winds down Yaps product after losing access to the X API

Jefferies’ Drops Bitcoin Over Quantum Computing Threat

Jefferies’ Drops Bitcoin Over Quantum Computing Threat

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn RSS Telegram
Coins League

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at Coins League

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITEMAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In