Back to Feed
RansomwareAug 10, 2026

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware uses Rust and decentralized infrastructure for victim communication and double extortion.

Summary

Microsoft Threat Intelligence has analyzed DeadLock, a new ransomware operation written in Rust. This financially motivated group employs a decentralized infrastructure to manage victim communications, negotiations, and data leak sites, in addition to using double extortion tactics to increase pressure on victims.

Full text

July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.

Entities

Rust (product)Microsoft (vendor)