DeadLock ransomware hides using exploited Polygon smart contracts
A new ransomware called "DeadLock" is exploiting Polygon smart contracts to hide its operations, according to cybersecurity firm Group-IB. Discovered in July, it has low exposure and few reported victims. However, its innovative methods pose risks to organizations. DeadLock uses smart contracts to store and rotate proxy addresses for communication with victims, making it hard to disrupt. This technique allows for infinite variations, and similar tactics have been noted in other malware cases, such as North Korean actors using "EtherHiding" to weaponize smart contracts for malicious purposes.
Cointelegraph·