LIVE · cybersecurity feed
Live wire
ransomwarehigh

DeadLock Ransomware Uses Rust and Decentralized Infrastructure

DeadLock ransomware, written in Rust, employs a decentralized infrastructure for victim communications and data leak operations, utilizing the Session messaging network and blockchain services. This architecture enhances its resilience against disruption. The ransomware engages in double extortion, encrypting files and threatening to leak stolen data, with over 80 organizations already targeted on its data leak site, primarily in Europe.

zeroday.news ·

Recent reports indicate the emergence of DeadLock ransomware, a new threat notable for its implementation in the Rust programming language and its adoption of a decentralized infrastructure. This design choice reportedly enhances the ransomware's operational resilience, particularly concerning its command-and-control mechanisms and data leak operations. The group behind DeadLock is said to employ a double extortion model, a common tactic in contemporary ransomware attacks.

The technical underpinnings of DeadLock ransomware leverage Rust, a systems programming language known for its memory safety and performance characteristics. The choice of Rust can make reverse engineering more challenging compared to some other languages, potentially increasing the development effort for security researchers. For its decentralized infrastructure, DeadLock reportedly utilizes the Session messaging network for victim communications. Session is a privacy-focused messenger that routes messages through a decentralized network of nodes, making it difficult to trace or disrupt.

In addition to Session, DeadLock is reported to integrate blockchain services into its operational framework. While the specific blockchain services are not detailed, such integration typically involves using blockchain for payment processing, data storage, or as a resilient communication channel. This decentralized approach for both communication and data leak infrastructure aims to make the ransomware's operations more resistant to takedowns or disruptions by law enforcement and cybersecurity agencies, as there is no single point of failure to target.

The DeadLock ransomware group employs a double extortion strategy. This involves not only encrypting a victim's files, rendering them inaccessible, but also exfiltrating sensitive data before encryption. The threat then becomes two-fold: pay the ransom to decrypt files, and pay again (or risk public exposure) to prevent the stolen data from being leaked. This tactic significantly increases pressure on victims to comply with ransom demands.

The data leak operations for DeadLock are reportedly conducted via a dedicated leak site. This site serves as a platform where stolen data from non-paying victims is published, further incentivizing organizations to pay the ransom to avoid reputational damage, regulatory fines, and competitive disadvantages. The reports indicate that over 80 organizations have already been listed on this data leak site.

Geographically, the DeadLock ransomware has primarily targeted organizations within Europe. This regional focus is consistent with the observed patterns of many ransomware groups, which often concentrate their efforts on specific regions based on various factors, including regulatory environments, economic conditions, and perceived vulnerabilities of local businesses.

The emergence of DeadLock ransomware highlights a continuing trend in the evolution of cyber threats, where attackers increasingly adopt advanced programming languages and decentralized technologies to enhance the robustness and evasiveness of their operations. The use of Rust, coupled with decentralized communication and data leak infrastructure, represents a strategic shift towards more resilient and difficult-to-disrupt ransomware campaigns, posing ongoing challenges for cybersecurity defenses globally.

ransomwaredeadlockrustdecentralized infrastructuredouble extortion
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

ddos

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]