DeadLock ransomware: Microsoft lists Defender protections

Microsoft Threat Intelligence describes DeadLock as a ransomware operation observed since July 2025 that combines encryption, data theft, and a resilient recovery and leak infrastructure. The new Microsoft report matters for organizations that protect Windows endpoints with Microsoft Defender and Defender XDR: it does not only describe malware internals, but also lists concrete settings that can reduce the impact of similar attacks.

What Microsoft observed about DeadLock

According to Microsoft, DeadLock has been deployed by multiple groups, including an affiliate of the Lynx and INC ransomware ecosystems. By July 2026, the operators had published more than 80 compromised organizations on their leak site; more than half of the named victims were in Europe. Microsoft lists sectors such as IT, manufacturing, transportation and logistics, hospitality, and consumer goods. This is therefore not a scenario limited to very large enterprises; it can also affect mid-sized environments.

The analyzed encryptor attempts to gain elevated privileges, stop security and backup services, clear event logs, and weaken recovery paths before encryption. Microsoft also documents that the malware can terminate processes belonging to security tools, backup and sync applications, and remote-access tools. For administrators, the important lesson is that protection controls need to be enabled and tested before an incident starts.

Why the infrastructure stands out

The recovery environment is the most unusual part of Microsoft’s analysis. DeadLock uses a local HTML application that includes chat, a leak blog, and a file browser. Some configuration data is stored on the Polygon blockchain, communication uses the Session network, and stolen data can be made available through Wasabi storage. Microsoft describes this model as more resilient against conventional takedown activity because a single domain or server is no longer the only point of failure.

For defenders, this means that blocking a few domains is not enough. Hardened endpoints, fast detection, controlled containment, and a tested response process for encryption and data exfiltration are more important.

Which protections Microsoft recommends

Microsoft recommends several controls that can be reviewed directly in Defender environments. They do not replace a complete incident response program, but they form a practical technical baseline for small IT teams.

  • Turn on cloud-delivered protection in Microsoft Defender Antivirus so new variants can be blocked faster.
  • Use Defender for Endpoint with EDR in block mode when another antivirus product is primary.
  • Configure tamper protection and always-on protection so attackers cannot simply stop security services.
  • Prepare automated investigation and remediation as well as automatic attack disruption in Defender XDR.
  • Evaluate Controlled Folder Access and attack surface reduction rules in audit mode, then harden them deliberately.

What small IT teams should check now

The report contains many technical details, but the first step is practical: verify whether the existing Microsoft security configuration is consistently applied. In organizations with 10 to 250 workstations, gaps often come from exceptions, legacy devices, or endpoints that are only partly managed.

  • Confirm that all production Windows devices are onboarded to Defender for Endpoint.
  • Compare active policies with Microsoft’s guidance for EDR in block mode, ASR rules, and automatic attack disruption.
  • Test which ASR rules can move to block mode without disrupting normal work.
  • Extend the incident response playbook to cover encryption, data exfiltration, device isolation, and reconnection.

Deadlines and priority: check now, no fixed cutoff

Microsoft does not name a migration deadline or product retirement date for DeadLock. The priority comes from the active threat context: the operation has been observed since 2025, had already published many victims by July 2026, and includes techniques that make recovery and forensics harder. The review should therefore not wait for the next major security project. A useful timeline is a short-term inventory, followed by controlled testing of ASR rules, EDR in block mode, and automated containment on representative devices.

Official Microsoft sources

If you want to know which Defender settings already apply in your tenant and where DeadLock-like attacks would still have too much room to move, we can review this in a Microsoft Security Assessmenttalk to us.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment