Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
DeadLock ransomware uses Polygon smart contracts to evade tracking

DeadLock ransomware uses Polygon smart contracts to evade tracking

Odaily星球日报Odaily星球日报2026/01/15 15:41
Show original

According to Odaily, Group-IB monitoring has revealed that the ransomware family DeadLock is currently using Polygon smart contracts to distribute and rotate proxy server addresses in order to evade security detection. This malware was first discovered in July 2025 and embeds JS code interacting with the Polygon network into HTML files, using RPC lists as gateways to obtain attacker-controlled server addresses. This technique is similar to the previously discovered EtherHiding, aiming to leverage decentralized ledgers to build covert communication channels that are difficult to block. DeadLock has already produced at least three variants, with the latest version embedding the encrypted communication application Session to communicate directly with victims.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!
© 2025 Bitget