Microsoft Threat Intelligence
2 published articles
Malware & Ransomware4 min read
Ransomware & Cybercrime
DeadLock ransomware puts its leak site on Polygon to dodge takedowns
Microsoft's teardown of DeadLock shows victim chats routed over Session and leak posts stored in Polygon smart contracts. The design resists the domain seizures that normally disrupt extortion operations, and it is already working: 80+ organizations published since July 2025.
2026-08-14
Cybersecurity3 min read
Cybersecurity
The wiper that bundles three flavors of destruction into a single backdoor
Microsoft found a Golang backdoor that packs three separate malware families into one implant. GigaWiper can wipe disks, encrypt files without decrypting, and maintain full remote access from a single binary.
2026-07-26