Netskope Threat Labs

DeadLock

ATP Sandbox Adv. HeuristicsAVNetskope IPS

DeadLock is a ransomware operation that emerged in 2024 and encrypts Windows systems after exfiltrating victim data. Researchers have observed its affiliates gaining initial access through exposed remote desktop services, and the group pressures victims through a leak site while demanding payment in cryptocurrency.

First seen
January 2026
Last seen
October 2026
Deadlock
Alert Name
Gen:Variant.Ransom.DeadLock.1
Generic.Ransomware.DeadLock.A.61F8F3F4
Script-PowerShell.Trojan.Deadlock
Win32.Ransomware.DeadLock