SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

Deadlock

💰 eCrimeMotivation: financialLast active: 2026-08-11First seen: 2026-07-10
0
linked CVEs
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundPublic SectorTechnologyTransportation/Logistics
Targeted regions
AOARBGBRCACHCZDEDKESGAGBHRHUINITLTMXNLNOPGPLPTSESGTRUSUYYT
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Source: ransomware_live · Collected: 2026-08-12
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs34
urlhttp://1rpc.io/matic2026-08-11
domaindeadlock.liveblog365.com2026-08-11
domainpolygon.meowrpc.com2026-08-11
sha256a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f42026-08-11
domaindeadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion2026-08-11
domaindeadlockblog.medianewsonline.com2026-08-11
domaindeadlockblog.great-site.net2026-08-11
domaindlock.liveblog365.com2026-08-11
sha2563c1b9df801b9abbb3684670822f367b5b8cda566b749f457821b6481606995b32026-03-27
sha2563cd5703d285ed2753434f14f8da933010ecfdc1e5009d0e438188aaf855016122026-03-27
md54374eb7807fbcb767ae3a6202b4dd8f82026-03-27
sha145f7f7e87d18fbe71745a0cc170ae08571c2ba0d2026-03-27
md5505d23c7a66a02239056ac3cfed241322026-03-27
md59a4dcce25a87819585aa0a1dd16186c82026-03-27
sha256be1037fac396cf54fb9e25c48e5b0039b3911bb8426cbf52c9433ba06c0685ce2026-03-27
md5c8e16b76ae25d2f27e581a9bef134ea82026-03-27
sha256c9cc95ff8f2998229394dfd31c2bd6b723e826a3ca5e008d2b5be19ba419ae2c2026-03-27
domainbiggoalsports.co.za2026-03-27
ip138.226.236.512026-03-27
ip94.74.164.2072026-03-27
urlhttp://138.226.236.51/prrq.php2026-03-27
urlhttp://94.74.164.207/prrq.php2026-03-27
urlhttps://94.74.164.207/prrq.php2026-03-27
urlhttps://biggoalsports.co.za/minif.php2026-03-27
urlhttps://envisionreg.com/wp-activate.php2026-03-27
urlhttps://nmsneustadtl.ac.at/xml.php2026-03-27
sha1e5ba4affd0f49a9e451aa913115cf16b481fe1dc2026-03-27
domainenvisionreg.com2026-03-27
domainguel.cm2026-03-27
domainhamzit.tra2026-03-27
domainnmsneustadtl.ac.at2026-03-27
domainsitecom.com2026-03-27
sha12204d64b82765db4598714fe8bc6e71a24958a7f2026-03-27
sha1235d6bdf25437b0b004152a263cb483aac08fd102026-03-27
📰 Threat Intel Coverage2
Digest reports mentioning this actor (incl. aliases)
DeadLock Ransomware: Smart Contracts for Malicious Purposesmatched as DeadLock2026-03-27
EDR killers explained: Beyond the driversmatched as DeadLock2026-03-19