Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly
DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

DeadLock ransomware abuses Polygon blockchain to rotate proxy servers quietly

January 16, 20264 Mins ReadNo Comments Bitcoin
Share
Facebook Twitter LinkedIn Pinterest Email

  • Group-IB published its report on Jan. 15 and said the method could make disruption harder for defenders.
  • The malware reads on-chain data, so victims do not pay gas fees.
  • Researchers said Polygon is not vulnerable, but the tactic could spread.

Ransomware groups usually rely on command-and-control servers to manage communications after breaking into a system.

But security researchers now say a low-profile strain is using blockchain infrastructure in a way that could be harder to block.

In a report published on Jan. 15, cybersecurity firm Group-IB said a ransomware operation known as DeadLock is abusing Polygon (POL) smart contracts to store and rotate proxy server addresses.

These proxy servers are used to relay communication between attackers and victims after systems are infected.

Because the information sits on-chain and can be updated anytime, researchers warned that this approach could make the group’s backend more resilient and tougher to disrupt.

Smart contracts used to store proxy information

Group-IB said DeadLock does not depend on the usual setup of fixed command-and-control servers.

Instead, once a machine is compromised and encrypted, the ransomware queries a specific smart contract deployed on the Polygon network.

That contract stores the latest proxy address that DeadLock uses to communicate. The proxy acts as a middle layer, helping attackers maintain contact without exposing their main infrastructure directly.

Since the smart contract data is publicly readable, the malware can retrieve the details without sending any blockchain transactions.

This also means victims do not need to pay gas fees or interact with wallets.

DeadLock only reads the information, treating the blockchain as a persistent source of configuration data.

Rotating infrastructure without malware updates

One reason this method stands out is how quickly attackers can change their communication routes.

Group-IB said the actors behind DeadLock can update the proxy address stored inside the contract whenever necessary.

That gives them the ability to rotate infrastructure without modifying the ransomware itself or pushing new versions into the wild.

In traditional ransomware cases, defenders can sometimes block traffic by identifying known command-and-control servers.

But with an on-chain proxy list, any proxy that gets flagged can be replaced simply by updating the contract’s stored value.

Once contact is established through the updated proxy, victims receive ransom demands along with threats that stolen information will be sold if payment is not made.

Why takedowns become more difficult

Group-IB warned that using blockchain data this way makes disruption significantly harder.

There is no single central server that can be seized, removed, or shut down.

Even if a specific proxy address is blocked, the attackers can switch to another one without having to redeploy the malware.

Since the smart contract remains accessible through Polygon’s distributed nodes worldwide, the configuration data can continue to exist even if the infrastructure on the attackers’ side changes.

Researchers said this gives ransomware operators a more resilient command-and-control mechanism compared with conventional hosting setups.

A small campaign with an inventive method

DeadLock was first observed in July 2025 and has stayed relatively low profile so far.

Group-IB said the operation has only a limited number of confirmed victims.

The report also noted that DeadLock is not linked to known ransomware affiliate programmes and does not appear to operate a public data leak site.

While that may explain why the group has received less attention than major ransomware brands, researchers said its technical approach deserves close monitoring.

Group-IB warned that even if DeadLock remains small, its technique could be copied by more established cybercriminal groups.

No Polygon vulnerability involved

The researchers stressed that DeadLock is not exploiting any vulnerability in Polygon itself.

It is also not attacking third-party smart contracts such as decentralised finance protocols, wallets, or bridges.

Instead, the attackers are abusing the public and immutable nature of blockchain data to hide configuration information.

Group-IB compared the technique to earlier “EtherHiding” approaches, where criminals used blockchain networks to distribute malicious configuration data.

Several smart contracts connected to the campaign were deployed or updated between August and Nov. 2025, according to the firm’s analysis.

Researchers said the activity remains limited for now, but the concept could be reused in many different forms by other threat actors.

While Polygon users and developers are not facing direct risk from this specific campaign, Group-IB said the case is another reminder that public blockchains can be misused to support off-chain criminal activity in ways that are difficult to detect and dismantle.


Share this article

Categories

Tags

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

Does RLUSD Eat XRP – Here’s What Onchain Data Say?

June 30, 2026

84% of Altcoins Trade Below 200-Day Moving Average

June 30, 2026

RLUSD Brings the Dollars, XRP Moves Them ; Analyst Explains Why There Is No Competition

June 29, 2026

ENA Price Reacts to BlackRock Partnership, But Traders Expected More

June 29, 2026
Add A Comment

Comments are closed.

Editors Picks

Tom Lee’s BitMine Adds $43 Million in Ethereum as Strategy Pauses Bitcoin Purchases

June 30, 2026

US starts clock to bring in ID checks for converting dollars to stablecoins but DeFi stays outside the rules

June 30, 2026

XRPL ReservedTxns: Schwartz’s Anti-Front-Running Fix

June 30, 2026

Luis Suárez Joins 1win Betwave for Exclusive World Cup Match Analysis

June 30, 2026
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

FRIC Price Up 30% As Wall Street Pepe ICO Smashes $63 Million Target

January 31, 2025

Ethereum and XRP Outperform Bitcoin

July 21, 2025

Best Crypto Betting Platforms 2026: Sports, eSports, and Live Markets

January 9, 2026
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$58,703.00-2.75%
  • ethereumEthereum(ETH)$1,578.05-2.79%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$546.54-2.55%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.04-2.64%
  • solanaSolana(SOL)$73.53-3.16%
  • tronTRON(TRX)$0.314807-1.98%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.59%
  • HyperliquidHyperliquid(HYPE)$65.44-2.06%
  • dogecoinDogecoin(DOGE)$0.072166-2.21%
  • RainRain(RAIN)$0.015746-1.39%
  • USDSUSDS(USDS)$1.000.02%
  • leo-tokenLEO Token(LEO)$9.25-2.94%
  • zcashZcash(ZEC)$400.20-1.62%
  • stellarStellar(XLM)$0.1851904.37%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$51.467.01%
  • moneroMonero(XMR)$305.48-2.36%
  • CantonCanton(CC)$0.140896-2.99%
  • cardanoCardano(ADA)$0.144677-1.83%
  • chainlinkChainlink(LINK)$7.20-3.51%
  • USD1USD1(USD1)$1.00-0.01%
  • daiDai(DAI)$1.000.01%
  • Ethena USDeEthena USDe(USDE)$1.00-0.02%
  • LABLAB(LAB)$13.85-9.56%
  • Gram (prev. Toncoin)Gram (prev. Toncoin)(GRAM)$1.54-4.83%
  • bitcoin-cashBitcoin Cash(BCH)$200.12-0.97%
  • litecoinLitecoin(LTC)$41.78-3.57%
  • Circle USYCCircle USYC(USYC)$1.13-0.06%
  • hedera-hashgraphHedera(HBAR)$0.069489-3.35%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • avalanche-2Avalanche(AVAX)$6.56-2.20%
  • suiSui(SUI)$0.70-1.23%
  • PayPal USDPayPal USD(PYUSD)$1.000.04%
  • shiba-inuShiba Inu(SHIB)$0.000004-1.52%
  • crypto-com-chainCronos(CRO)$0.053672-1.52%
  • tether-goldTether Gold(XAUT)$4,007.920.06%
  • nearNEAR Protocol(NEAR)$1.80-5.03%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.47%
  • BittensorBittensor(TAO)$202.58-2.89%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.057646-1.99%
  • pax-goldPAX Gold(PAXG)$4,010.350.05%
  • uniswapUniswap(UNI)$2.79-6.28%
  • AsterAster(ASTER)$0.630.10%
  • okbOKB(OKB)$78.33-1.43%
  • OndoOndo(ONDO)$0.311817-2.26%
  • HTX DAOHTX DAO(HTX)$0.000002-2.86%
  • WorldcoinWorldcoin(WLD)$0.407244-4.56%
  • Falcon USDFalcon USD(USDF)$1.000.08%
  • Ripple USDRipple USD(RLUSD)$1.00-0.02%
  • polkadotPolkadot(DOT)$0.82-0.86%
  • usddUSDD(USDD)$1.000.01%
  • mantleMantle(MNT)$0.415416-2.33%
  • BFUSDBFUSD(BFUSD)$1.00-0.03%
  • aaveAave(AAVE)$85.17-8.56%
  • Pi NetworkPi Network(PI)$0.114430-2.54%
  • MorphoMorpho(MORPHO)$1.904.00%
  • SkySky(SKY)$0.0529000.14%
  • internet-computerInternet Computer(ICP)$2.10-3.29%
  • bitget-tokenBitget Token(BGB)$1.59-2.15%
  • ethereum-classicEthereum Classic(ETC)$6.93-2.82%
  • DeXeDeXe(DEXE)$22.910.98%
  • United StablesUnited Stables(U)$1.00-0.01%
  • PepePepe(PEPE)$0.000002-2.60%
  • Blockchain CapitalBlockchain Capital(BCAP)$106.970.00%
  • quant-networkQuant(QNT)$65.17-1.12%
  • ​​Stable​​Stable(STABLE)$0.038430-0.16%
  • Spiko EU T-Bills Money Market FundSpiko EU T-Bills Money Market Fund(EUTBL)$1.200.00%
  • MemeCoreMemeCore(M)$0.6915.69%
  • kucoin-sharesKuCoin(KCS)$6.72-3.47%
  • Janus Henderson Anemoy Treasury FundJanus Henderson Anemoy Treasury Fund(JTRSY)$1.110.01%
  • Invesco Short Duration US Government Securities FundInvesco Short Duration US Government Securities Fund(USTB)$11.130.03%
  • USDGOUSDGO(USDGO)$1.00-0.01%
  • AudieraAudiera(BEAT)$2.938.79%
  • kaspaKaspa(KAS)$0.029499-1.02%
  • render-tokenRender(RENDER)$1.52-3.55%
  • cosmosCosmos Hub(ATOM)$1.50-2.09%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.069824-2.12%
  • justJUST(JST)$0.086760-0.74%
  • USDtbUSDtb(USDTB)$1.000.02%
  • algorandAlgorand(ALGO)$0.082266-5.01%
  • nexoNEXO(NEXO)$0.71-3.30%
  • JupiterJupiter(JUP)$0.209730-4.56%
  • ADIADI(ADI)$5.520.75%
  • gatechain-tokenGate(GT)$6.45-3.34%
  • Janus Henderson Anemoy AAA CLO FundJanus Henderson Anemoy AAA CLO Fund(JAAA)$1.040.02%
  • 币安人生 (BinanceLife)币安人生 (BinanceLife)(币安人生)$0.68-2.11%
  • BeldexBeldex(BDX)$0.086769-3.27%
  • VelvetVelvet(VELVET)$1.58-6.88%
  • EthenaEthena(ENA)$0.070724-10.00%
  • Spiko Amundi Overnight Swap Fund (EUR)Spiko Amundi Overnight Swap Fund (EUR)(EURSAFO)$1.15-0.07%
  • GHOGHO(GHO)$1.000.00%
  • Pump.funPump.fun(PUMP)$0.001453-3.30%
  • Venice TokenVenice Token(VVV)$12.38-9.24%
  • filecoinFilecoin(FIL)$0.73-1.68%
  • FlareFlare(FLR)$0.006473-1.66%
  • YLDSYLDS(YLDS)$1.000.00%
  • xdce-crowd-saleXDC Network(XDC)$0.027921-0.66%
  • Usual USDUsual USD(USD0)$1.000.00%