ransomware microsoft patches professional services patch management cybersecurity

Recommended Microsoft Patches: The DeadLock Blockchain Problem And What To Fix This Week

DeadLock ransomware hides its command-and-control on Polygon blockchain, dodging takedowns. Here are the recommended Microsoft patches to apply now.

Dylan Natter
6 min read

I want to tell you about a lock on a door that nobody can pick, break, or reach the manufacturer of. That is roughly the problem security teams are staring at this week, and it is worth two minutes of your Friday.

Microsoft Threat Intelligence went public with details on a ransomware group called DeadLock. What makes DeadLock interesting is not that it encrypts your files. Everybody does that now. What makes it interesting is where it hides its brain.

Most ransomware groups run their command-and-control, the servers that tell the malware what to do, on infrastructure that lives somewhere. A data center. A hosting provider. A box in a country that does not answer subpoenas. And when that box has an address, law enforcement can eventually find it, seize it, and cut the head off the snake. That is how a lot of takedowns work. You find the server, you grab the server, the operation goes dark.

DeadLock moved parts of that infrastructure onto the Polygon blockchain, using smart contracts as a configuration store that points victims to its negotiation chat and its leak site. A blockchain contract is not sitting in a rack somewhere waiting for a warrant. Microsoft assesses that this design likely makes portions of the group’s communication, leak-hosting, and negotiation infrastructure more resilient, letting operators recover from some disruption while keeping continuity for victims. It is not immune to takedown. The group still depends on an off-chain proxy server staying reachable, on public blockchain endpoints, and on cloud storage that holds the stolen files. But it raises the cost of every one of those takedowns.

What Microsoft actually reported

As of July 2026, DeadLock operators had published more than 80 compromised organizations on their data leak site, with more than half in Europe. Microsoft identified victims across information technology, mining, transportation and logistics, manufacturing, hospitality, and consumer goods. The group runs double extortion, which means they steal your data before they encrypt it, so paying to decrypt does not stop them from leaking what they already took. Microsoft observed DeadLock being deployed by multiple groups, including an affiliate of the Lynx and INC ransomware ecosystems, which tells you this is not a hobby crew.

Here is the part I want professional services firms to sit with. The blockchain trick is a resilience feature for the attacker. It does not change how they get in. They still get in the old way. Unpatched software. A stolen password. A phishing email that lands. The scary headline is about how hard they are to shut down after the fact. The thing you actually control is stopping them from getting in at all.

Which brings me to patches.

Groups like DeadLock, and the affiliates they recruit, live on known vulnerabilities that never got closed. Not zero-days. Old, patched, documented holes that a business meant to fix and never did. So here is the Friday work, framed around Microsoft’s own guidance.

Apply the current Patch Tuesday cumulative update. Microsoft ships security fixes on the second Tuesday of every month. If your Windows fleet is more than one cycle behind, that is your first job. Every month you skip is another set of documented entry points left open. Check your update history and confirm the latest cumulative update is actually installed, not just downloaded.

Close the Exchange and Outlook gaps. Microsoft has issued repeated advisories for on-premises Exchange Server and Outlook flaws that ransomware affiliates actively use for initial access. If you still run any on-prem Exchange, verify you are on a supported cumulative update and that the latest security update is applied on top of it. This is one of the most common ways a firm gets a foot in the door.

Enforce multifactor authentication across Microsoft 365. A patch does nothing against a password that leaked in a breach two years ago. Microsoft Research found that MFA reduced the risk of account compromise by 99.22 percent across the studied population, and by 98.56 percent for accounts whose passwords had already leaked. Turn it on for every account, including the admin accounts you think are too important to bother.

Turn on the built-in ransomware protections you already pay for. Controlled folder access and attack surface reduction rules ship inside Microsoft Defender. Attack surface reduction rules target the risky software behavior that attackers commonly exploit through malware. They sit there, off, waiting.

For a law firm, an accounting practice, an architecture studio, the calculation is simple. Your client files are the business. A double-extortion crew does not need to encrypt anything to hurt you. They just need to threaten to publish what they took. Patches are the boring, unglamorous work that keeps you off their victim list in the first place.

Common Questions

Does the Polygon blockchain angle mean my usual defenses do not work anymore? No. The blockchain trick affects how hard DeadLock is to dismantle after it is running, not how it breaks in. Patching, MFA, and email filtering still stop the initial compromise, which is the part you control.

We are a small firm. Are we really a target for a group this size? Smaller professional services firms are attractive precisely because they hold valuable client data and often run behind on patches. Affiliates pick targets by opportunity, not by size.

Which Microsoft patch should we apply first if we can only do one thing today? Confirm the latest Windows cumulative update is installed across every machine, then enforce MFA on Microsoft 365. Those two moves close the widest set of doors fastest.

Does paying the ransom end the threat? No. Because DeadLock steals data before encrypting, paying for a decryption key does nothing to stop them from leaking or selling what they already took.

centrexIT has been the IT team Professional Services organizations across the West have trusted since 2002. If patch management is one of those things that keeps slipping to next quarter, it is worth a conversation about who owns it. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/

Sources

Found this helpful? Share it with your network.
Written by
Dylan Natter

The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.

Meet Our Team