Deadlock Ransomware Claims Attack on Thai Engineering Firm Tesco Engineer Co.
The Deadlock ransomware group has claimed responsibility for a targeted cyberattack against Tesco Engineer Co. Ltd., a prominent…
> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
/actor/deadlock-ransomware/ · 1 intel report
Deadlock Ransomware is an emerging ransomware operation that appeared in 2024, targeting mid-market enterprises across multiple sectors with a double-extortion approach combining file encryption with data theft. The group operates a Tor-based data leak site where victim information is published following failed ransom negotiations, applying maximum pressure on organisations to comply with payment demands.
Deadlock has targeted organisations across healthcare, manufacturing, legal services, and technology sectors, with victims reported across North America and Europe. Their ransomware payload demonstrates competent technical development, encrypting both Windows and Linux environments and specifically targeting VMware ESXi hypervisor infrastructure to maximise operational disruption through virtual machine encryption.
The group's initial access methods include exploitation of exposed Remote Desktop Protocol (RDP) services, VPN appliance vulnerabilities, and phishing campaigns delivering malicious macro-embedded documents. Following initial access, Deadlock operators conduct manual reconnaissance to identify high-value data and critical systems before deploying their encryption payload.
Deadlock represents one of several new ransomware operations that emerged in 2024 as experienced cybercriminals sought to establish independent operations or fill gaps left by law enforcement disruptions of major RaaS platforms. Their relatively rapid victim acquisition rate suggests either experienced operators or successful affiliate recruitment drawing on existing criminal networks.
Analysis of historical telemetry associated with this threat actor reveals a highly adaptive operational tempo. Initial campaigns were characterized by opportunistic exploitation of known vulnerabilities (N-days) in perimeter-facing infrastructure. However, recent forensic investigations indicate a significant evolution in their Tactics, Techniques, and Procedures (TTPs). The group has increasingly integrated sophisticated defense evasion mechanisms, utilizing bespoke malware droppers and "Living off the Land" (LotL) binaries to bypass traditional endpoint detection systems.
The targeting profile of this collective has expanded considerably over the past year. While initial operations primarily focused on opportunistic financial extortion within the SME sector, current intelligence suggests a strategic pivot towards high-value targets within critical infrastructure, government logistics, and regional financial institutions. This shift implies an alignment with broader geopolitical objectives or the acquisition of more advanced Initial Access Broker (IAB) networks.
To defend against the specific methodologies employed by this actor, organizations must prioritize the following mitigation strategies:
Note: This dossier is continuously updated as new intelligence regarding the actor's operations becomes available. Analysts are advised to monitor associated C2 infrastructure for shifts in targeting priorities.
The Deadlock ransomware group has claimed responsibility for a targeted cyberattack against Tesco Engineer Co. Ltd., a prominent…