Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Enterprises across the US, Europe, and Turkey
Incident: Deployment of DeadLock ransomware utilizing decentralized infrastructure for extortion.
Impact: Data encryption, exfiltration, and high resilience against infrastructure takedown attempts.
Attacker: DeadLock
Analysis: DeadLock has evolved its extortion infrastructure by utilizing the Polygon blockchain and Session messaging to ensure its communication and leak sites remain online despite disruption efforts. The group employs a hybrid cryptographic approach and resource-aware throttling to avoid detection and maintain system stability during encryption. This shift toward decentralized infrastructure represents a significant tactical evolution in ransomware resilience.
Recommendations: Implement strict egress filtering to block unauthorized remote access tools like AnyDesk; Enforce robust offline backup strategies to mitigate double extortion pressure; Monitor for unusual file renaming patterns involving the .dlock extension
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source