B
今週中
DeadLockランサムウェアは、Polygonブロックチェーン、Session通信ネットワーク、Wasabiクラウドストレージを利用して、分散型の勒索インフラ…
📌 一言でいうと
DeadLockランサムウェアは、Polygonブロックチェーン、Session通信ネットワーク、Wasabiクラウドストレージを利用して、分散型の勒索インフラを構築しています。これにより、単一サーバーへの依存を減らし、C2サーバーの変更をスマートコントラクト経由で柔軟に行うことが可能です。また、Rust製の暗号化プログラムはCPU/メモリ負荷を監視して動作を調整し、検知回避やシステムの応答性維持を図っています。
🔍該当判定
- 社内でWindows PCやサーバーを運用しており、外部からの不正アクセス対策(VPNやファイアウォール)が不十分な状態である
- IT、製造、運輸、物流、宿泊などの業界で事業を展開している
- バックアップをクラウドや外部ストレージに保存せず、社内ネットワーク上のサーバーのみで管理している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
バックアップのオフライン保存、エンドポイント保護製品(EDR)の導入、不審なネットワーク通信(特にブロックチェーンノードやSessionプロトコルへの通信)の監視を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】DeadLockランサムウェアの分散型インフラ利用について
お疲れさまです。DeadLockランサムウェアに関する技術情報共有です。
■ 概要
DeadLockは、PolygonブロックチェーンのスマートコントラクトをC2のポインタとして利用し、Sessionネットワークで通信、Wasabiストレージで漏洩データを管理する分散型インフラを採用しています。また、Rust製暗号化エンジンはシステム負荷を監視して動作を制御する機能を備えています。
■ 影響範囲
- 特定の製品脆弱性ではなく、複数の攻撃グループによるキャンペーンとして観測されています。
■ 対応手順
1. ネットワーク監視において、不審なブロックチェーン公開ノードへの通信やSessionプロトコルの利用がないか確認してください。
2. EDR等のログで、Rust製バイナリによる不審なファイル暗号化挙動を検知できるよう設定を確認してください。
3. 重要なデータのオフラインバックアップを再確認してください。
■ 参考情報
- Microsoft Threat Intelligence
対応優先度: 中
対応期限: 継続的な監視
お疲れさまです。DeadLockランサムウェアに関する技術情報共有です。
■ 概要
DeadLockは、PolygonブロックチェーンのスマートコントラクトをC2のポインタとして利用し、Sessionネットワークで通信、Wasabiストレージで漏洩データを管理する分散型インフラを採用しています。また、Rust製暗号化エンジンはシステム負荷を監視して動作を制御する機能を備えています。
■ 影響範囲
- 特定の製品脆弱性ではなく、複数の攻撃グループによるキャンペーンとして観測されています。
■ 対応手順
1. ネットワーク監視において、不審なブロックチェーン公開ノードへの通信やSessionプロトコルの利用がないか確認してください。
2. EDR等のログで、Rust製バイナリによる不審なファイル暗号化挙動を検知できるよう設定を確認してください。
3. 重要なデータのオフラインバックアップを再確認してください。
■ 参考情報
- Microsoft Threat Intelligence
対応優先度: 中
対応期限: 継続的な監視
Subject: [Intel] DeadLock Ransomware Decentralized Infrastructure
Dear team,
We are sharing technical intelligence regarding the DeadLock ransomware.
■ Overview
DeadLock employs a decentralized infrastructure using Polygon blockchain smart contracts for C2 redirection, the Session network for communication, and Wasabi cloud storage for exfiltrated data. The Rust-based encryptor is designed to monitor system resources to avoid crashing the victim's machine during encryption.
■ Scope
- Observed across multiple sectors globally (IT, Mining, Logistics, Manufacturing, Hospitality).
■ Recommended Actions
1. Monitor network traffic for unusual connections to public blockchain nodes or Session protocol traffic.
2. Ensure EDR/XDR policies are tuned to detect anomalous file encryption patterns associated with Rust binaries.
3. Verify the integrity and isolation of offline backups.
■ Reference
- Microsoft Threat Intelligence
Priority: Medium
Deadline: Ongoing monitoring
Dear team,
We are sharing technical intelligence regarding the DeadLock ransomware.
■ Overview
DeadLock employs a decentralized infrastructure using Polygon blockchain smart contracts for C2 redirection, the Session network for communication, and Wasabi cloud storage for exfiltrated data. The Rust-based encryptor is designed to monitor system resources to avoid crashing the victim's machine during encryption.
■ Scope
- Observed across multiple sectors globally (IT, Mining, Logistics, Manufacturing, Hospitality).
■ Recommended Actions
1. Monitor network traffic for unusual connections to public blockchain nodes or Session protocol traffic.
2. Ensure EDR/XDR policies are tuned to detect anomalous file encryption patterns associated with Rust binaries.
3. Verify the integrity and isolation of offline backups.
■ Reference
- Microsoft Threat Intelligence
Priority: Medium
Deadline: Ongoing monitoring