Microsoft Threat Intelligence is tracking DeadLock as an emerging financially motivated ransomware operation. The group uses a Rust-based encryptor and combines file encryption with data theft and extortion pressure.
The practical lesson
The ransomware name may change, but the defensive priorities remain consistent: reduce the chance of initial access, limit how far an attacker can move, and make recovery possible without relying on the attacker.
Recommended response
- Apply security updates promptly, especially to internet-facing systems.
- Use MFA and remove unnecessary administrator privileges.
- Maintain monitored endpoint detection and response.
- Keep tested backups with at least one protected or immutable copy.
- Segment important systems where practical.
- Have a documented incident-response and recovery process.
Backups are particularly important, but they should be tested. A backup that has never been restored is only an assumption.
Source: Microsoft Threat Intelligence, DeadLock ransomware analysis, 10 August 2026.