Exelasis A.I CyberSecurity Scoring
Exelasis
Company Information
Website:https://www.exelasis.com
Employees number:5
Number of followers:14,000
NAICS:541514
Industry Type:Computer and Network Security
Homepage:exelasis.com
Exelasis Risk Score (AI oriented)
Between 0 and 549
ExelasisComputer and Network Security
Updated:
11/08/2026
11/08/2026
508/1000
Critical
C
Exelasis Global Score (TPRM)
xxxx
ExelasisComputer and Network Security
Score locked

ExelasisCritical
Current Score
508C (CRITICAL)
01000
2 incidents
-159 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
508
JULY 2026
658
Ransomware
01 Jul 2026 • Exelasis
DeadLock: DeadLock ransomware uses blockchain to resist infrastructure takedown
DeadLock Ransomware Leverages Blockchain for Resilient Operations
499
CRITICAL-159
EXE1786487016
DeadLock Ransomware Leverages Blockchain for Resilient Operations
The DeadLock ransomware operation, active since mid-2025, has adopted a decentralized infrastructure to evade disruption, using blockchain-backed services to secure communications and data-leak activities. Employing double-extortion tactics encrypting files while threatening to leak stolen data the group has targeted 80 organizations by July 2025, primarily in Europe, across sectors including IT, mining, transportation, manufacturing, hospitality, and consumer goods.
Microsoft researchers identified multiple deployment groups behind DeadLock, including an affiliate previously linked to the Lynx and INC ransomware ecosystems. The operation stands out for its use of the Polygon blockchain to store configuration data and leak-site posts, replacing traditional Tor URLs with smart contract queries to retrieve command-and-control (C2) addresses. This tactic, while common among cybercriminals, remains rare in ransomware.
DeadLock further enhances resilience by using the decentralized Session network for encrypted victim communications and Wasabi cloud storage for hosting stolen files. These measures allow operators to swap proxies without modifying victim-facing apps, reducing reliance on takedown-prone domains. However, Microsoft notes that disruptions remain possible public Polygon RPC endpoints must stay accessible, and Wasabi-hosted files can still be removed.
The ransomware’s encryption scheme avoids systems in the former Soviet Union, CIS region, Iran, Syria, Oman, and Yemen. After disabling backups, virtualization, and clearing the Recycle Bin, it encrypts non-system directories using XChaCha20 keys protected by Curve25519 elliptic curve cryptography. To minimize detection, DeadLock caps resource usage at 29% memory and 70% CPU, allowing victims limited system access during encryption. Large files are partially encrypted in 512-byte blocks for speed, while encrypted data is marked with a victim-specific ID and the `.dlock` extension.
Ransom demands are made in Bitcoin or Monero, with attackers offering a decryptor, data-deletion assurances, breach details, and security recommendations in exchange for payment. Microsoft’s analysis underscores DeadLock’s evasive techniques while highlighting potential vulnerabilities in its decentralized infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
658
MAY 2026
656
APRIL 2026
653
MARCH 2026
653
FEBRUARY 2026
651
JANUARY 2026
649
DECEMBER 2025
647
NOVEMBER 2025
645
OCTOBER 2025
643
SEPTEMBER 2025
641
JULY 2025
748
Ransomware
01 Jul 2025 • Exelasis
DeadLock: DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock Ransomware Attack
634
CRITICAL-114
EXE1786436694
DeadLock Ransomware: A Sophisticated Threat with Decentralized Resilience
First detected in July 2025, DeadLock is a financially motivated ransomware operation that employs double extortion encrypting enterprise data while threatening to leak stolen files. The group’s tactics blend traditional intrusion methods with decentralized infrastructure, making disruption difficult.
### Key Tactics and Technical Details
DeadLock’s malware, written in Rust, begins by XOR-decoding an embedded configuration before checking system language settings. If the victim’s system is set to Russian, Ukrainian, Belarusian, several CIS languages, or select Middle Eastern countries (Iran, Syria, Oman, Yemen), the malware self-deletes, suggesting regional avoidance rather than direct attribution.
On non-elevated systems, DeadLock forces UAC prompts via `ShellExecuteW` to gain administrative privileges. Once elevated, it enables high-level privileges (`SeDebugPrivilege`, `SeBackupPrivilege`, `SeRestorePrivilege`) to disable security tools and recovery mechanisms.
The ransomware aggressively disrupts defenses by:
- Stopping critical services (Windows Defender, VSS, Hyper-V, Active Directory, backup software).
- Killing processes (MsMpEng, PowerShell, Task Manager, cloud-sync clients, remote-access tools).
- Clearing Windows Event Logs (Security, System, Application) and disabling custom telemetry channels via registry modifications.
- Emptying Recycle Bins and registering a custom `.dlock` file extension with a unique icon.
### Encryption and Post-Attack Workflow
DeadLock uses XChaCha20 encryption with per-file Curve25519 ECDH keys, making decryption without the attacker’s private key practically impossible. Large files are partially encrypted in 512-byte blocks to accelerate impact on databases, VMs, and backups. The malware throttles resource usage (pausing if CPU exceeds 70% or memory hits 29%) to evade behavioral detection.
After encryption, victims receive a local HTML recovery chat (`RECOVERY_CHAT.<UID>.html`), which connects to Polygon smart contracts for proxy addresses and leak-blog content. Communications are routed through Session’s onion-routed network, while stolen files may be hosted on Wasabi’s S3-compatible storage. This decentralized infrastructure complicates takedown efforts, though dependencies on public RPC endpoints and proxies remain exploitable.
### Victim Profile and Attribution
By July 2026, Microsoft’s Threat Intelligence identified over 80 victims, with more than half in Europe. Targeted sectors include IT, mining, logistics, manufacturing, hospitality, and consumer goods. Microsoft links DeadLock to multiple threat groups, including affiliates from the Lynx and INC ransomware ecosystems, suggesting an affiliate-driven access model rather than a single organized crew.
### Indicators of Compromise (IOCs)
- SHA-256: `a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4` (DeadLock encryptor)
- Leak sites:
- `deadlock.liveblog365[.]com`
- `dlock.liveblog365[.]com`
- `deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion`
DeadLock’s aggressive anti-forensic measures, sound cryptography, and decentralized command-and-control make it a persistent and adaptive threat in the ransomware landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Exelasis ??
What was Exelasis's A.I Rankiteo Cyber Score in July 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in June 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in May 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in April 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in March 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in February 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in January 2026 ??
What was Exelasis's A.I Rankiteo Cyber Score in December 2025 ??
What was Exelasis's A.I Rankiteo Cyber Score in November 2025 ??
What was Exelasis's A.I Rankiteo Cyber Score in October 2025 ??
What was Exelasis's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Exelasis's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Exelasis ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Exelasis's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?