The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. The ransomware adopts a selective encryption model to exclude certain directories, file extensions, and file names from encryption. Perhaps the most unusual aspect of the ransomware is its use of an HTML note ("RECOVERY_CHAT.<UID>.html") that's dropped in all drive root directories and all Desktop folders. The two wallet addresses used by the threat actor are below -0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe, which stores the proxy server URL ("138.226.236[.