DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of Clinical/Pharmacovigilance Records — Threadlinqs Intelligence
As of 2026-08-01, DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of Clinical/Pharmacovigilance Records is a high-severity ransomware threat attributed to DeadLock (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1809 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: DeadLock · Russia · FINANCIAL
Spanish biopharmaceutical company DIATER (Laboratorio de Diagnóstico y Aplicaciones Terapéuticas, SA), a Madrid-based allergy-diagnostics and immunotherapy manufacturer owned by China's WORG
On 2026-07-28 at 14:51 UTC, the DeadLock ransomware group's leak site listed DIATER (Laboratorio de Diagnóstico y Aplicaciones Terapéuticas, SA) as a victim of a double-extortion attack. DIATER is a Madrid-headquartered biopharmaceutical company founded in 1999 specializing in molecular allergy diagnostics and allergen-specific immunotherapy (ASIT); since 2023 it has operated as part of Chinese biopharmaceutical group WORG Pharmaceuticals (Zhejiang) Co., Ltd., which runs an integrated R&D/production subsidiary spanning Shanghai and Madrid, and DIATER's products are marketed through Allergen Servilab (Spain) and Diater Laboratorios (Spain, Portugal, Germany). Public reporting (DataBreaches.net, mirrored by APD Noticias) states DeadLock claims to have exfiltrated user-folder directories, general documents, Quality Management (QM) files, and material tied to DIATER's EDICOM electronic-document/EDI integration, including clinical histories and pharmacovigilance data the company has been required to retain for approximately ten years. Because DIATER handles allergy diagnostics and immunotherapy products used directly on patients, the exposed record set plausibly includes sensitive personal health data of patients and healthcare professionals, raising GDPR Article 9 (special-category data) exposure concerns. No ransom demand figure, confirmed initial-intrusion date, or itemized data inventory has been made public as of this writing.
DeadLock is a financially motivated, non-nation-state-affiliated ransomware operation first observed by researchers in mid-2025. It differentiates itself technically by using Polygon blockchain smart contracts (primary contract 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe, secondary 0xAc9f868E285C8141617a97b85b667f229147815c) to rotate proxy-server addresses via cost-free read-only eth_call methods, and by pairing this with kernel-level EDR-termination capability (BYOVD — bring-your-own-vulnerable-driver) and Session-messenger-based victim negotiation. Victim files are appended with a `.dlock` extension plus a short per-victim identifier (e.g., `report.pdf.A1B2C3.dlock`), and the encryptor drops `HOW_RECOVER.<ID>.txt` and `RECOVERY_CHAT.<ID>.html` ransom-note/negotiation artifacts plus a custom `.ico` file, changing the desktop wallpaper to reinforce the extortion message; payment is demanded in Bitcoin or Monero. The malware performs a language/locale check and refuses to execute on Cyrillic-configured systems, a common self-preservation behavior among CIS-region-linked ransomware crews, consistent with the 'Russian-origin' attribution used in initial triage, though public threat-intel reporting characterizes DeadLock as an independent criminal enterprise without confirmed nation-state sponsorship (attribution confidence: LOW-to-MEDIUM, circumstantial).
Across its broader campaign, DeadLock resurfaced in June 2026 after roughly eleven months of relative public silence, posting 75 new victims that month and entering leak-site leaderboards in second place; by 2026-06-16 its clearnet leak site (deadlock.liveblog365[.]com) listed approximately 80 victims, roughly 57% concentrated in the Europe/Russia region with the remainder spread across APAC, North America, South America, and the Middle East/Africa, and with Manufacturing as the most frequently hit sector alongside Construction & Engineering and Professional Services. Documented DeadLock intrusion tradecraft (aggregated across public reporting, not confirmed victim-specific for DIATER) spans initial access via compromised domain/local accounts and external remote services (sometimes staged through compromised WordPress sites), Windows-native execution (PowerShell, cmd, WMI), service-based persistence, BYOVD privilege escalation and kernel-level EDR/security-tool impairment, LSASS credential dumping (Mimikatz), internal reconnaissance (SoftPerfect NetScan, PCHunter64), lateral movement via RDP and SMB admin shares, staged collection from network shares, A
Target sectors: health, biopharmaceutical, pharmacy, manufacturing, professional services, construction and engineering
Target regions: spain, Europe, APAC, North America, 005 - South America, Middle East and Africa
Detections & IOCs
As of 2026-08-18, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078.002, T1078.003, T1133, T1059.001, T1059.003, T1047, T1543.003, T1068, T1055, T1211