What's Hot

    Belarus establishes rules for ‘crypto banks’: check out the details

    January 16, 2026

    Why a record 13M crypto projects are now dead as Bitcoin critics still claim “anyone can launch a token”

    January 16, 2026

    PUMP eyes $0.0033 on release of creator-focused callout feature

    January 16, 2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Crypto News: Latest Cryptocurrency News and Analysis
    • Home
    • Business

      Fidelity Buys 7.4% Of Bitcoin Mining Company Marathon Digital Holdings

      February 11, 2021

      Twitter Reacts as Auto Driver Begins Accepting Crypto as Payment

      February 11, 2021

      HSBC Becomes Latest Bank to Suspend Payments to Crypto

      February 4, 2021

      Bitcoin Holds Support; Approaching $50K Resistance

      February 4, 2021

      Cryptocurrency Prices Today: Bitcoin Up Over $47,000, Ether Rises 3%

      February 3, 2021
    • Technology
      1. Business
      2. Insights
      3. View All

      Fidelity Buys 7.4% Of Bitcoin Mining Company Marathon Digital Holdings

      February 11, 2021

      Twitter Reacts as Auto Driver Begins Accepting Crypto as Payment

      February 11, 2021

      HSBC Becomes Latest Bank to Suspend Payments to Crypto

      February 4, 2021

      Bitcoin Holds Support; Approaching $50K Resistance

      February 4, 2021

      Belarus establishes rules for ‘crypto banks’: check out the details

      January 16, 2026

      Why a record 13M crypto projects are now dead as Bitcoin critics still claim “anyone can launch a token”

      January 16, 2026

      PUMP eyes $0.0033 on release of creator-focused callout feature

      January 16, 2026

      State Street Bets on Tokenisation to Modernise Wall Street’s Core Infrastructure

      January 16, 2026

      Bitcoin Climbs as Elon Musk Says Tesla ‘Likely’ to Accept it Again

      March 16, 2021

      Can Cryptocurrency Be Hacked, Stolen Or Scammed? How Can You Be Safe?

      February 11, 2021

      How Investors Can Get In On Crypto Without Actually Buying Any

      February 4, 2021

      Ethereum Just Underwent a Major Change – Hence, The 25% Jump in a Week!

      February 4, 2021
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      State Street Bets on Tokenisation to Modernise Wall Street’s Core Infrastructure

      January 16, 2026

      Iran’s Crypto Surge Reflects Economic Flight—and Sanctions Pressure

      January 16, 2026

      BofA’s Moynihan Warns Interest-Bearing Stablecoins Could Drain US$6T From Banks

      January 16, 2026

      Tokenisation Leaders Push Back on Coinbase’s Claim That Crypto Bill “Bans” Tokenised Stocks

      January 16, 2026

      Why a record 13M crypto projects are now dead as Bitcoin critics still claim “anyone can launch a token”

      January 16, 2026

      Forget silver, Copper’s AI-fueled explosion exposes a “higher for longer” trap that most crypto traders are ignoring

      January 16, 2026

      Bitcoin just touched a critical price point but this order book signal suggests the move to $100k might backfire

      January 16, 2026

      Discord is suddenly locking down servers for the same alarming reason X just purged these crypto developers

      January 16, 2026

      Belarus establishes rules for ‘crypto banks’: check out the details

      January 16, 2026

      PUMP eyes $0.0033 on release of creator-focused callout feature

      January 16, 2026

      Kaito winds down Yaps product after losing access to the X API

      January 16, 2026

      South Korea limits foreign crypto exchange access as Google Play enforces licensing

      January 16, 2026

      $7.35 in Coins Couldo Top $8M at GreatCollections Jan. 18

      January 15, 2026

      Heritage’s FUN Auctions Open Strong With $7.17 Million

      January 14, 2026

      U.S. Mint Signals Pricing Review Amid Record Silver Prices

      January 13, 2026

      PNG Opens Nominations for 2026 Numismatic Awards

      January 13, 2026

      Belarus establishes rules for ‘crypto banks’: check out the details

      January 16, 2026

      Why a record 13M crypto projects are now dead as Bitcoin critics still claim “anyone can launch a token”

      January 16, 2026

      PUMP eyes $0.0033 on release of creator-focused callout feature

      January 16, 2026

      State Street Bets on Tokenisation to Modernise Wall Street’s Core Infrastructure

      January 16, 2026
    • Markets
    • Get In Touch
    Crypto News: Latest Cryptocurrency News and Analysis
    Home » DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly
    Eurozone

    DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

    行政By 行政January 16, 2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

    • Group-IB published its report on Jan. 15 and said the method could make disruption harder for defenders.
    • The malware reads on-chain data, so victims do not pay gas fees.
    • Researchers said Polygon is not vulnerable, but the tactic could spread.

    Ransomware groups usually rely on command-and-control servers to manage communications after breaking into a system.

    But security researchers now say a low-profile strain is using blockchain infrastructure in a way that could be harder to block.

    In a report published on Jan. 15, cybersecurity firm Group-IB said a ransomware operation known as DeadLock is abusing Polygon (POL) smart contracts to store and rotate proxy server addresses.

    These proxy servers are used to relay communication between attackers and victims after systems are infected.

    Because the information sits on-chain and can be updated anytime, researchers warned that this approach could make the group’s backend more resilient and tougher to disrupt.

    Smart contracts used to store proxy information

    Group-IB said DeadLock does not depend on the usual setup of fixed command-and-control servers.

    Instead, once a machine is compromised and encrypted, the ransomware queries a specific smart contract deployed on the Polygon network.

    That contract stores the latest proxy address that DeadLock uses to communicate. The proxy acts as a middle layer, helping attackers maintain contact without exposing their main infrastructure directly.

    Since the smart contract data is publicly readable, the malware can retrieve the details without sending any blockchain transactions.

    This also means victims do not need to pay gas fees or interact with wallets.

    DeadLock only reads the information, treating the blockchain as a persistent source of configuration data.

    Rotating infrastructure without malware updates

    One reason this method stands out is how quickly attackers can change their communication routes.

    Group-IB said the actors behind DeadLock can update the proxy address stored inside the contract whenever necessary.

    That gives them the ability to rotate infrastructure without modifying the ransomware itself or pushing new versions into the wild.

    In traditional ransomware cases, defenders can sometimes block traffic by identifying known command-and-control servers.

    But with an on-chain proxy list, any proxy that gets flagged can be replaced simply by updating the contract’s stored value.

    Once contact is established through the updated proxy, victims receive ransom demands along with threats that stolen information will be sold if payment is not made.

    Why takedowns become more difficult

    Group-IB warned that using blockchain data this way makes disruption significantly harder.

    There is no single central server that can be seized, removed, or shut down.

    Even if a specific proxy address is blocked, the attackers can switch to another one without having to redeploy the malware.

    Since the smart contract remains accessible through Polygon’s distributed nodes worldwide, the configuration data can continue to exist even if the infrastructure on the attackers’ side changes.

    Researchers said this gives ransomware operators a more resilient command-and-control mechanism compared with conventional hosting setups.

    A small campaign with an inventive method

    DeadLock was first observed in July 2025 and has stayed relatively low profile so far.

    Group-IB said the operation has only a limited number of confirmed victims.

    The report also noted that DeadLock is not linked to known ransomware affiliate programmes and does not appear to operate a public data leak site.

    While that may explain why the group has received less attention than major ransomware brands, researchers said its technical approach deserves close monitoring.

    Group-IB warned that even if DeadLock remains small, its technique could be copied by more established cybercriminal groups.

    No Polygon vulnerability involved

    The researchers stressed that DeadLock is not exploiting any vulnerability in Polygon itself.

    It is also not attacking third-party smart contracts such as decentralised finance protocols, wallets, or bridges.

    Instead, the attackers are abusing the public and immutable nature of blockchain data to hide configuration information.

    Group-IB compared the technique to earlier “EtherHiding” approaches, where criminals used blockchain networks to distribute malicious configuration data.

    Several smart contracts connected to the campaign were deployed or updated between August and Nov. 2025, according to the firm’s analysis.

    Researchers said the activity remains limited for now, but the concept could be reused in many different forms by other threat actors.

    While Polygon users and developers are not facing direct risk from this specific campaign, Group-IB said the case is another reminder that public blockchains can be misused to support off-chain criminal activity in ways that are difficult to detect and dismantle.


    Share this article

    Categories

    Tags

    Crime,Blockchain News,Polygon#DeadLock #ransomware #abuses #Polygon #blockchain #rotate #proxy #servers #quietly1768552841

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    行政
    • Website

    Related Posts

    Belarus establishes rules for ‘crypto banks’: check out the details

    January 16, 2026

    PUMP eyes $0.0033 on release of creator-focused callout feature

    January 16, 2026

    Kaito winds down Yaps product after losing access to the X API

    January 16, 2026

    South Korea limits foreign crypto exchange access as Google Play enforces licensing

    January 16, 2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    January 20, 2021

    Jack Dorsey Says Bitcoin Will Unite The World

    January 15, 2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    January 15, 2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

    We're social. Connect with us:

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Belarus establishes rules for ‘crypto banks’: check out the details

    January 16, 2026

    Why a record 13M crypto projects are now dead as Bitcoin critics still claim “anyone can launch a token”

    January 16, 2026

    PUMP eyes $0.0033 on release of creator-focused callout feature

    January 16, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook Twitter Instagram Pinterest
    • Home
    • Business
    • Markets
    • Technology
    • Contact us
    © 2026 ThemeSphere. Designed by WPfastworld.

    Type above and press Enter to search. Press Esc to cancel.