• bitcoinBitcoin (BTC) $ 95,368.00
  • ethereumEthereum (ETH) $ 3,287.70
  • tetherTether (USDT) $ 0.999676
  • bnbBNB (BNB) $ 926.36
  • xrpXRP (XRP) $ 2.06
  • usd-coinUSDC (USDC) $ 0.999815
  • staked-etherLido Staked Ether (STETH) $ 3,287.69
  • tronTRON (TRX) $ 0.309123
  • dogecoinDogecoin (DOGE) $ 0.139561
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.391085
  • moneroMonero (XMR) $ 714.23
  • wrapped-stethWrapped stETH (WSTETH) $ 4,022.98
  • whitebitWhiteBIT Coin (WBT) $ 57.26
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,576.41
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 94,922.00
  • bitcoin-cashBitcoin Cash (BCH) $ 580.65
  • wrapped-eethWrapped eETH (WEETH) $ 3,568.66
  • usdsUSDS (USDS) $ 0.999927
  • chainlinkChainlink (LINK) $ 13.64
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999809
  • leo-tokenLEO Token (LEO) $ 8.89
  • wethWETH (WETH) $ 3,287.17
  • stellarStellar (XLM) $ 0.226002
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 95,287.00
  • zcashZcash (ZEC) $ 413.45
  • suiSui (SUI) $ 1.77
  • ethena-usdeEthena USDe (USDE) $ 0.999379
  • avalanche-2Avalanche (AVAX) $ 13.68
  • hyperliquidHyperliquid (HYPE) $ 24.67
  • litecoinLitecoin (LTC) $ 71.86
  • hedera-hashgraphHedera (HBAR) $ 0.117565
  • canton-networkCanton (CC) $ 0.134611
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • usdt0USDT0 (USDT0) $ 0.999556
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.167289
  • daiDai (DAI) $ 0.999839
  • susdssUSDS (SUSDS) $ 1.09
  • the-open-networkToncoin (TON) $ 1.71
  • crypto-com-chainCronos (CRO) $ 0.101001
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999934
  • polkadotPolkadot (DOT) $ 2.11
  • usd1-wlfiUSD1 (USD1) $ 0.999078
  • uniswapUniswap (UNI) $ 5.29
  • rainRain (RAIN) $ 0.009648
  • mantleMantle (MNT) $ 0.960362
  • memecoreMemeCore (M) $ 1.60
  • bittensorBittensor (TAO) $ 279.22
  • bitget-tokenBitget Token (BGB) $ 3.70
  • aaveAave (AAVE) $ 169.73
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,610.11
  • okbOKB (OKB) $ 113.98
  • internet-computerInternet Computer (ICP) $ 4.13
  • nearNEAR Protocol (NEAR) $ 1.71
  • falcon-financeFalcon USD (USDF) $ 0.997840
  • jito-staked-solJito Staked SOL (JITOSOL) $ 177.03
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,291.43
  • ethereum-classicEthereum Classic (ETC) $ 12.52
  • pax-goldPAX Gold (PAXG) $ 4,628.42
  • ethenaEthena (ENA) $ 0.221511
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.202591
  • aster-2Aster (ASTER) $ 0.706773
  • solanaSolana (SOL) $ 141.20
  • pump-funPump.fun (PUMP) $ 0.002717
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.87
  • htx-daoHTX DAO (HTX) $ 0.000002
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.150740
  • binance-staked-solBinance Staked SOL (BNSOL) $ 154.10
  • global-dollarGlobal Dollar (USDG) $ 0.999767
  • worldcoin-wldWorldcoin (WLD) $ 0.557740
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • kucoin-sharesKuCoin (KCS) $ 11.37
  • ripple-usdRipple USD (RLUSD) $ 0.999955
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • wbnbWrapped BNB (WBNB) $ 925.27
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,794.03
  • aptosAptos (APT) $ 1.78
  • skySky (SKY) $ 0.059028
  • bfusdBFUSD (BFUSD) $ 0.999181
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999758
  • kaspaKaspa (KAS) $ 0.045213
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,490.14
  • cosmosCosmos Hub (ATOM) $ 2.47
  • gatechain-tokenGate (GT) $ 10.39
  • hash-2Provenance Blockchain (HASH) $ 0.022306
  • ondo-financeOndo (ONDO) $ 0.377015
  • arbitrumArbitrum (ARB) $ 0.206385
  • render-tokenRender (RENDER) $ 2.20
  • algorandAlgorand (ALGO) $ 0.127576
  • filecoinFilecoin (FIL) $ 1.48
  • quant-networkQuant (QNT) $ 73.37
  • official-trumpOfficial Trump (TRUMP) $ 5.34
  • ignition-fbtcFunction FBTC (FBTC) $ 95,822.00
  • myx-financeMYX Finance (MYX) $ 5.48
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 95,619.00
  • midnight-3Midnight (NIGHT) $ 0.062462
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 95,103.00
  • dashDash (DASH) $ 81.00
  • vechainVeChain (VET) $ 0.011483
  • usddUSDD (USDD) $ 0.999446
  • nexoNEXO (NEXO) $ 0.964146
  • flare-networksFlare (FLR) $ 0.011153
  • bonkBonk (BONK) $ 0.000010
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,504.14
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,570.04
  • usdtbUSDtb (USDTB) $ 0.998968
  • story-2Story (IP) $ 2.43
  • xdce-crowd-saleXDC Network (XDC) $ 0.043716
  • sei-networkSei (SEI) $ 0.119987
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.96
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999797
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.996733
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 95,237.00
  • ousgOUSG (OUSG) $ 113.97
  • morphoMorpho (MORPHO) $ 1.39
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.012004
  • clbtcclBTC (CLBTC) $ 96,264.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,512.30
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 164.06
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.04
  • jupiter-exchange-solanaJupiter (JUP) $ 0.217095
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • beldexBeldex (BDX) $ 0.089985
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,493.68
  • usdaiUSDai (USDAI) $ 1.00
  • optimismOptimism (OP) $ 0.338126
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,286.47
  • blockstackStacks (STX) $ 0.366643
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.988367
  • wrapped-flareWrapped Flare (WFLR) $ 0.011147
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999864
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.272162
  • tezosTezos (XTZ) $ 0.579272
  • chilizChiliz (CHZ) $ 0.059615
  • curve-dao-tokenCurve DAO (CRV) $ 0.414236
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • usual-usdUsual USD (USD0) $ 0.996278
  • c8ntinuumc8ntinuum (CTM) $ 0.131110
  • tbtctBTC (TBTC) $ 95,238.00
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.93
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,286.76
  • gtethGTETH (GTETH) $ 3,286.89
  • spx6900SPX6900 (SPX) $ 0.562327
  • lido-daoLido DAO (LDO) $ 0.610172
  • injective-protocolInjective (INJ) $ 5.14
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998866
  • aerodrome-financeAerodrome Finance (AERO) $ 0.549190
  • a7a5A7A5 (A7A5) $ 0.012693
  • ghoGHO (GHO) $ 0.999649
  • true-usdTrueUSD (TUSD) $ 0.999511
  • msolMarinade Staked SOL (MSOL) $ 191.07
  • riverRiver (RIVER) $ 24.52
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,549.09
  • flokiFLOKI (FLOKI) $ 0.000050
  • celestiaCelestia (TIA) $ 0.551319
  • ether-fiEther.fi (ETHFI) $ 0.726883
  • fasttokenFasttoken (FTN) $ 1.09
  • stader-ethxStader ETHx (ETHX) $ 3,544.34
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,681.59
  • lighterLighter (LIT) $ 1.83
  • doublezeroDoubleZero (2Z) $ 0.128144
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • decredDecred (DCR) $ 25.45
  • sbtc-2sBTC (SBTC) $ 95,855.00
  • the-graphThe Graph (GRT) $ 0.040343
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.213352
  • syrupMaple Finance (SYRUP) $ 0.371481
  • newton-projectAB (AB) $ 0.004386
  • starknetStarknet (STRK) $ 0.083651
  • staked-aaveStaked Aave (STKAAVE) $ 170.24
  • bittorrentBitTorrent (BTT) $ 0.00000043
  • usdbUSDB (USDB) $ 0.999267
  • justJUST (JST) $ 0.041058
  • jasmycoinJasmyCoin (JASMY) $ 0.008181
  • iotaIOTA (IOTA) $ 0.095018
  • sun-tokenSun Token (SUN) $ 0.020754
  • bitcoin-svBitcoin SV (BSV) $ 19.61
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.25
  • conflux-tokenConflux (CFX) $ 0.075210
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,286.91
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.923506
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.380384
  • gnosisGnosis (GNO) $ 143.99
  • cap-usdCap USD (CUSD) $ 0.992188
  • dogwifcoindogwifhat (WIF) $ 0.378313
  • crvusdcrvUSD (CRVUSD) $ 0.997885
  • telcoinTelcoin (TEL) $ 0.003870
  • pyth-networkPyth Network (PYTH) $ 0.064201
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 95,233.00
  • fartcoinFartcoin (FARTCOIN) $ 0.363758
  • apenftAINFT (NFT) $ 0.00000036
  • humanityHumanity (H) $ 0.196768
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.139575
  • kinesis-goldKinesis Gold (KAU) $ 149.19

DeadLock Ransomware Using Polygon Smart Contracts to Evade Detection

0 2

DeadLock Ransomware Using Polygon Smart Contracts to Evade Detection

A newly discovered strain of ransomware is using Polygon smart contracts for proxy server address rotation and distribution to infiltrate devices, cybersecurity firm Group‑IB warned on Thursday.

The malware, dubbed DeadLock, was first identified in July 2025 and has so far attracted little attention because it lacks a public affiliate program and a data‑leak site and has infected only a limited number of victims, according to the company.

🚨 DeadLock Ransomware: When Blockchain Meets Cybercrime

Group-IB has uncovered a sophisticated new threat rewriting the ransomware playbook. DeadLock leverages Polygon smart contracts to rotate proxy addresses, a stealthy, under-reported technique that bypasses traditional… pic.twitter.com/rlPu9gZd5F

— Group-IB Global (@GroupIB) January 15, 2026

“Although it’s low profile and yet low impact, it applies innovative methods that showcases an evolving skillset which might become dangerous if organizations do not take this emerging threat seriously,” Group-IB said in a blog.

DeadLock’s use of smart contracts to deliver proxy addresses is “an interesting method where attackers can literally apply infinite variants of this technique; imagination is the limit,” the firm noted. Group-IB pointed to a recent report by the Google Threat Intelligence Group highlighting the use of a similar technique called “EtherHiding” employed by North Korean hackers.

What is EtherHiding?

EtherHiding is a campaign disclosed last year in which DPRK hackers used the Ethereum blockchain to conceal and deliver malicious software. Victims are typically lured through compromised websites—often WordPress pages—that load a small snippet of JavaScript. That code then pulls the hidden payload from the blockchain, allowing attackers to distribute malware in a way that is highly resilient to takedowns.

Both EtherHiding and DeadLock repurpose public, decentralized ledgers as covert channels that are difficult for defenders to block or dismantle. DeadLock takes advantage of rotating proxies, which are servers that regularly change the IP of a user, making it harder to track or block.

While Group‑IB admitted that “initial access vectors and other important stages of the attacks remain unknown at this point,” it said DeadLock infections rename encrypted files with a “.dlock” extension and replace desktop backgrounds with ransom notes.

Newer versions also warn victims that sensitive data has been stolen and could be sold or leaked if a ransom is not paid. At least three variants of the malware have been identified so far.

Earlier versions relied on allegedly compromised servers, but researchers now believe the group operates its own infrastructure. The key innovation, however, lies in how DeadLock retrieves and manages server addresses.



“Group-IB researchers uncovered JS code within the HTML file that interacts with a smart contract over the Polygon network,” it explained. “This RPC list contains the available endpoints for interacting with the Polygon network or blockchain, acting as gateways that connect applications to the blockchain’s existing nodes.”

Its most recently observed version also embeds communication channels between the victim and attacker. DeadLock drops a HTML file that acts as a wrapper around the encrypted messaging app Session.

“The main purpose of the HTML file is to facilitate direct communication between the DeadLock operator and the victim,” Group‑IB said.

Source

Leave A Reply

Your email address will not be published.