DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware uses Rust and decentralized infrastructure for victim communication and double extortion.
Summary
Microsoft Threat Intelligence has analyzed DeadLock, a new ransomware operation written in Rust. This financially motivated group employs a decentralized infrastructure to manage victim communications, negotiations, and data leak sites, in addition to using double extortion tactics to increase pressure on victims.
Full text
July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.