First detected in July 2025, this group has already compiled a list of over 80 organizations on its leak site known as the DeadLock blog This article explores extorts deadlock encrypted. . The majority of these targets are found across Europe, but attacks have also affected various regions including Asia, North America, South America, and Africa.

The operation follows a typical double-extortion model: initially stealing sensitive information, then locking files while threatening a public data leak to intensify pressure on victims. Unlike traditional websites and servers that can be easily disrupted by law enforcement or hosting providers, it leverages blockchain-backed services and Session messaging networks for negotiation, publication leaks, and communication with victims.

DeadLock Steals Encrypts Extorts DeadLock is encrypted using an XOR key derived from a configuration file that includes the victim's ID, attacker’s public key, list of processes to stop, excluded files and directories, ransom-note content, geofencing settings, and system language detection before it begins encrypting files. It aims to stop Windows Defender, Volume Shadow Copy, backup services, Hyper-V, Active Directory-related services, OneDrive, Dropbox, Google Drive, AnyDesk, PowerShell, Task Manager, and other tools that might block encryption or assist in recovery. File Extension ..dlock