IT Starts with CareNeed support?
Talk to KPTech1300 303 173

DeadLock ransomware: what small businesses should do now

Microsoft Threat Intelligence is tracking DeadLock as an emerging financially motivated ransomware operation. The group uses a Rust-based encryptor and combines file encryption with data theft and extortion pressure.

The practical lesson

The ransomware name may change, but the defensive priorities remain consistent: reduce the chance of initial access, limit how far an attacker can move, and make recovery possible without relying on the attacker.

Recommended response

  • Apply security updates promptly, especially to internet-facing systems.
  • Use MFA and remove unnecessary administrator privileges.
  • Maintain monitored endpoint detection and response.
  • Keep tested backups with at least one protected or immutable copy.
  • Segment important systems where practical.
  • Have a documented incident-response and recovery process.

Backups are particularly important, but they should be tested. A backup that has never been restored is only an assumption.

Source: Microsoft Threat Intelligence, DeadLock ransomware analysis, 10 August 2026.