The post DeadLock Malware Exploits Polygon Smart Contracts to Hide appeared on BitcoinEthereumNews.com. A recently-discovered ransomware dubbed “DeadLock” is stealthilyThe post DeadLock Malware Exploits Polygon Smart Contracts to Hide appeared on BitcoinEthereumNews.com. A recently-discovered ransomware dubbed “DeadLock” is stealthily

DeadLock Malware Exploits Polygon Smart Contracts to Hide

2026/01/16 18:28
2 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

A recently-discovered ransomware dubbed “DeadLock” is stealthily exploiting Polygon smart contracts to rotate and distribute proxy addresses, say researchers at cybersecurity firm Group-IB.

The company reported on Thursday that the DeadLock ransomware, first discovered in July, has seen “low exposure” as it isn’t tied to any known data leak site or affiliate programs and has a “limited number of reported victims.”

However, Group-IB warned that even though the ransomware is “low profile,” it uses “innovative methods” that could be dangerous to organizations that don’t take the malware seriously, “especially since the abuse of this specific blockchain for malicious purposes has not been widely reported.”

DeadLock leverages Polygon smart contracts to store and rotate proxy server addresses used to communicate with victims. Code embedded in the ransomware interacts with a specific smart contract address and uses a function to dynamically update command-and-control infrastructure.

Once victims have been infected with the malware and encryption has occurred, DeadLock threatens them with a ransom note and the selling of stolen data if their demands are not met.

Infinite variants of the technique can be applied

By storing proxy addresses on-chain, Group-IB said DeadLock creates infrastructure that is extremely difficult to disrupt, as there is no central server to take down, and blockchain data persists indefinitely across distributed nodes worldwide.

Related: Hackers find new way to hide malware in Ethereum smart contracts

“This exploit of smart contracts to deliver proxy addresses is an interesting method where attackers can literally apply infinite variants of this technique; imagination is the limit,” it added.

HTML file with an embedded Session private messenger to contact the threat actor. Source: Group-IB

North Korean threat actors found “EtherHiding” 

Weaponizing smart contracts for malware dissemination is not new, with Group-IB noting a tactic called “EtherHiding” that Google reported in October. 

A North Korean threat actor dubbed “UNC5342” used this technique, “which consists of leveraging transactions on public blockchains to store and retrieve malicious payloads,” it said. 

EtherHiding involves embedding malicious code, often in the form of JavaScript payloads, within a smart contract on a public blockchain, explained Google at the time. 

Magazine: Trump rules out SBF pardon, Bitcoin in ‘boring sideways’: Hodler’s Digest

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/deadlock-ransomware-hides-exploited-polygon-smart-contracts?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Opportunità di mercato
Logo Smart Blockchain
Valore Smart Blockchain (SMART)
$0.005228
$0.005228$0.005228
+1.45%
USD
Grafico dei prezzi in tempo reale di Smart Blockchain (SMART)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!