Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Exelasis

Exelasis Vendor Cyber Rating & Cyber Score

exelasis.com

Exelasis specialises in elite security testing, red teaming, and incident response services, offering comprehensive cybersecurity solutions to safeguard your organisation. Our security team, comprised of industry-leading experts with top certifications, brings pioneering expertise to the table. Equipped with state-of-the-art tools and methodologies, the Exelasis team evaluates and enhances your organisation's security posture with precision and innovation.


Exelasis A.I CyberSecurity Scoring

Exelasis
Company Information
Website:https://www.exelasis.com
Employees number:5
Number of followers:14,000
NAICS:541514
Industry Type:Computer and Network Security
Homepage:exelasis.com
Exelasis Risk Score (AI oriented)
Between 0 and 549
logo
ExelasisComputer and Network Security
Updated:
11/08/2026
508/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Exelasis Global Score (TPRM)
xxxx
logo
ExelasisComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Exelasis
ExelasisCritical
Current Score
508C (CRITICAL)
01000
2 incidents
-159 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
508Before Incident
JULY 2026
658Before Incident
Ransomware
01 Jul 2026Exelasis
DeadLock: DeadLock ransomware uses blockchain to resist infrastructure takedown

DeadLock Ransomware Leverages Blockchain for Resilient Operations

499After Incident
CRITICAL-159
EXE1786487016
DeadLock Ransomware Leverages Blockchain for Resilient Operations The DeadLock ransomware operation, active since mid-2025, has adopted a decentralized infrastructure to evade disruption, using blockchain-backed services to secure communications and data-leak activities. Employing double-extortion tactics encrypting files while threatening to leak stolen data the group has targeted 80 organizations by July 2025, primarily in Europe, across sectors including IT, mining, transportation, manufacturing, hospitality, and consumer goods. Microsoft researchers identified multiple deployment groups behind DeadLock, including an affiliate previously linked to the Lynx and INC ransomware ecosystems. The operation stands out for its use of the Polygon blockchain to store configuration data and leak-site posts, replacing traditional Tor URLs with smart contract queries to retrieve command-and-control (C2) addresses. This tactic, while common among cybercriminals, remains rare in ransomware. DeadLock further enhances resilience by using the decentralized Session network for encrypted victim communications and Wasabi cloud storage for hosting stolen files. These measures allow operators to swap proxies without modifying victim-facing apps, reducing reliance on takedown-prone domains. However, Microsoft notes that disruptions remain possible public Polygon RPC endpoints must stay accessible, and Wasabi-hosted files can still be removed. The ransomware’s encryption scheme avoids systems in the former Soviet Union, CIS region, Iran, Syria, Oman, and Yemen. After disabling backups, virtualization, and clearing the Recycle Bin, it encrypts non-system directories using XChaCha20 keys protected by Curve25519 elliptic curve cryptography. To minimize detection, DeadLock caps resource usage at 29% memory and 70% CPU, allowing victims limited system access during encryption. Large files are partially encrypted in 512-byte blocks for speed, while encrypted data is marked with a victim-specific ID and the `.dlock` extension. Ransom demands are made in Bitcoin or Monero, with attackers offering a decryptor, data-deletion assurances, breach details, and security recommendations in exchange for payment. Microsoft’s analysis underscores DeadLock’s evasive techniques while highlighting potential vulnerabilities in its decentralized infrastructure.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Stolen data leaked as part of double-extortion tacticsSystems Affected: Non-system directories encrypted, backups disabled, virtualization disruptedOperational Impact: Limited system access during encryption (resource usage capped at 29% memory and 70% CPU)
DATA BREACH
Type Of Data Compromised: Stolen data (unspecified types)Data Exfiltration: Yes (threatened as part of double-extortion)Data Encryption: XChaCha20 keys protected by Curve25519 elliptic curve cryptography
JUNE 2026
658Before Incident
MAY 2026
656Before Incident
APRIL 2026
653Before Incident
MARCH 2026
653Before Incident
FEBRUARY 2026
651Before Incident
JANUARY 2026
649Before Incident
DECEMBER 2025
647Before Incident
NOVEMBER 2025
645Before Incident
OCTOBER 2025
643Before Incident
SEPTEMBER 2025
641Before Incident
JULY 2025
748Before Incident
Ransomware
01 Jul 2025Exelasis
DeadLock: DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files

DeadLock Ransomware Attack

634After Incident
CRITICAL-114
EXE1786436694
DeadLock Ransomware: A Sophisticated Threat with Decentralized Resilience First detected in July 2025, DeadLock is a financially motivated ransomware operation that employs double extortion encrypting enterprise data while threatening to leak stolen files. The group’s tactics blend traditional intrusion methods with decentralized infrastructure, making disruption difficult. ### Key Tactics and Technical Details DeadLock’s malware, written in Rust, begins by XOR-decoding an embedded configuration before checking system language settings. If the victim’s system is set to Russian, Ukrainian, Belarusian, several CIS languages, or select Middle Eastern countries (Iran, Syria, Oman, Yemen), the malware self-deletes, suggesting regional avoidance rather than direct attribution. On non-elevated systems, DeadLock forces UAC prompts via `ShellExecuteW` to gain administrative privileges. Once elevated, it enables high-level privileges (`SeDebugPrivilege`, `SeBackupPrivilege`, `SeRestorePrivilege`) to disable security tools and recovery mechanisms. The ransomware aggressively disrupts defenses by: - Stopping critical services (Windows Defender, VSS, Hyper-V, Active Directory, backup software). - Killing processes (MsMpEng, PowerShell, Task Manager, cloud-sync clients, remote-access tools). - Clearing Windows Event Logs (Security, System, Application) and disabling custom telemetry channels via registry modifications. - Emptying Recycle Bins and registering a custom `.dlock` file extension with a unique icon. ### Encryption and Post-Attack Workflow DeadLock uses XChaCha20 encryption with per-file Curve25519 ECDH keys, making decryption without the attacker’s private key practically impossible. Large files are partially encrypted in 512-byte blocks to accelerate impact on databases, VMs, and backups. The malware throttles resource usage (pausing if CPU exceeds 70% or memory hits 29%) to evade behavioral detection. After encryption, victims receive a local HTML recovery chat (`RECOVERY_CHAT.<UID>.html`), which connects to Polygon smart contracts for proxy addresses and leak-blog content. Communications are routed through Session’s onion-routed network, while stolen files may be hosted on Wasabi’s S3-compatible storage. This decentralized infrastructure complicates takedown efforts, though dependencies on public RPC endpoints and proxies remain exploitable. ### Victim Profile and Attribution By July 2026, Microsoft’s Threat Intelligence identified over 80 victims, with more than half in Europe. Targeted sectors include IT, mining, logistics, manufacturing, hospitality, and consumer goods. Microsoft links DeadLock to multiple threat groups, including affiliates from the Lynx and INC ransomware ecosystems, suggesting an affiliate-driven access model rather than a single organized crew. ### Indicators of Compromise (IOCs) - SHA-256: `a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4` (DeadLock encryptor) - Leak sites: - `deadlock.liveblog365[.]com` - `dlock.liveblog365[.]com` - `deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion` DeadLock’s aggressive anti-forensic measures, sound cryptography, and decentralized command-and-control make it a persistent and adaptive threat in the ransomware landscape.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Enterprise data encrypted and exfiltratedSystems Affected: Windows systems, databases, VMs, backups, Active DirectoryOperational Impact: Disruption of critical services, backup software, and security toolsBrand Reputation Impact: Potential reputational damage due to data leaksIdentity Theft Risk: High (if PII was exfiltrated)Payment Information Risk: High (if payment data was exfiltrated)
DATA BREACH
Enterprise dataPotentially PII/payment informationSensitivity Of Data: High (encrypted and exfiltrated)Data Encryption: XChaCha20 with Curve25519 ECDH keysDatabasesVMsBackupsOther enterprise files

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Exelasis ?
?
What was Exelasis's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Exelasis's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Exelasis's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Exelasis ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Exelasis's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?