BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines. Known victims: 5
Objectives
Executive Summary
BQTLock is a ransomware-as-a-service (RaaS) operation identified in 2025, linked to pro-Palestinian hacktivist networks. The group employs AES-256/RSA-4096 encryption and demands payment in Monero cryptocurrency with 48-hour deadlines. Their campaigns exhibit wave-like patterns, targeting a broad range of organizations without apparent sector-specific focus.
Goals & Targeting
BQTLock's primary motivation is organizational-gain, with goals centered around financial profit through ransomware activities. Their targeting strategy appears to be opportunistic rather than sector-specific, reflecting a broad-based approach to identifying vulnerable organizations. This makes it challenging for any particular industry or geography to claim immunity from their attacks. The group's association with hacktivist networks may influence their selection of targets in certain regions or industries, but no specific sectors or countries have been conclusively identified as primary targets.
Enhanced Description
BQTLock emerged in July 2025 as a ransomware operation characterized by its use of advanced encryption standards (AES-256 and RSA-4096) and Monero payment demands. The group is associated with pro-Palestinian hacktivist networks, suggesting potential political motivations underlying their criminal activities. Their modus operandi involves wave-based campaigns, where multiple victims are targeted in quick succession, followed by strict 48-hour deadlines for ransom payments. This approach indicates a focus on maximizing financial gain through efficient campaign execution. BQTLock's reliance on established encryption protocols and payment mechanisms suggests a degree of technical proficiency, though their operational scale may still be developing as they establish themselves in the threat landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BQTLock's campaigns are relatively new but demonstrate a methodical approach with clear deadlines and payment mechanisms. Their wave-based targeting suggests an operational model aimed at maximizing the number of potential victims while minimizing the time required to execute attacks. Notable for their association with hacktivist groups, BQTLock may leverage these networks to expand their reach or identify targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat actor BQTLock is confidently identified as a ransomware operation first seen in July 2025. Their association with hacktivist networks and use of specific encryption protocols are well-documented. However, gaps remain in understanding their full technical capabilities, campaign tradecraft, and precise targeting criteria outside of general opportunism.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics