Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors bqtlock

Description

BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

BQTLock is a ransomware-as-a-service (RaaS) operation identified in 2025, linked to pro-Palestinian hacktivist networks. The group employs AES-256/RSA-4096 encryption and demands payment in Monero cryptocurrency with 48-hour deadlines. Their campaigns exhibit wave-like patterns, targeting a broad range of organizations without apparent sector-specific focus.

Goals & Targeting

BQTLock's primary motivation is organizational-gain, with goals centered around financial profit through ransomware activities. Their targeting strategy appears to be opportunistic rather than sector-specific, reflecting a broad-based approach to identifying vulnerable organizations. This makes it challenging for any particular industry or geography to claim immunity from their attacks. The group's association with hacktivist networks may influence their selection of targets in certain regions or industries, but no specific sectors or countries have been conclusively identified as primary targets.

Enhanced Description

BQTLock emerged in July 2025 as a ransomware operation characterized by its use of advanced encryption standards (AES-256 and RSA-4096) and Monero payment demands. The group is associated with pro-Palestinian hacktivist networks, suggesting potential political motivations underlying their criminal activities. Their modus operandi involves wave-based campaigns, where multiple victims are targeted in quick succession, followed by strict 48-hour deadlines for ransom payments. This approach indicates a focus on maximizing financial gain through efficient campaign execution. BQTLock's reliance on established encryption protocols and payment mechanisms suggests a degree of technical proficiency, though their operational scale may still be developing as they establish themselves in the threat landscape.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) operation
  • AES-256 and RSA-4096 encryption algorithms
  • Monero cryptocurrency demand for payments
  • Wave-based campaign techniques
  • Strict 48-hour ransom deadlines

MITRE ATT&CK Tactics

Exfiltration of Data
Network Access Persistence Across Organizational Boundaries
Spear-Phishing
Intrusion

ATT&CK Techniques

T1055
T1505.001
T1566.001
T1059.003

Software / Tooling

Ransomware (AES-256/RSA-4096)
Monero wallet interaction tools
Wave campaign planning tools
Spear-phishing components

Campaigns & Victims

BQTLock's campaigns are relatively new but demonstrate a methodical approach with clear deadlines and payment mechanisms. Their wave-based targeting suggests an operational model aimed at maximizing the number of potential victims while minimizing the time required to execute attacks. Notable for their association with hacktivist groups, BQTLock may leverage these networks to expand their reach or identify targets.

IOC Patterns

  • Ransomware with AES-256/RSA-4096 encryption
  • Monero payment demands via Tor-based wallets
  • Spear-phishing emails with malicious links
  • Wave-like patterns of attack campaigns
  • Windows-based file encryption activities

Recommended Actions

  • Implement robust backup and restore mechanisms to mitigate ransomware impacts.
  • Train employees to recognize spear-phishing attempts and suspicious emails.
  • Monitor network traffic for异常加密活动和Monero交易相关行为,特别是在波状攻击可能发生的时间段。
  • Conduct regular vulnerability assessments to identify and patch potential attack vectors.
  • 部署多因素认证 (MFA) 和网络安全解决方案以防止未经授权的网络访问。
  • Establish an incident response plan tailored to ransomware incidents, including isolation and containment strategies.

Suggested Tags

APT
ransomware
financial-gain
cyber-criminal
Middle East

Confidence Assessment

The threat actor BQTLock is confidently identified as a ransomware operation first seen in July 2025. Their association with hacktivist networks and use of specific encryption protocols are well-documented. However, gaps remain in understanding their full technical capabilities, campaign tradecraft, and precise targeting criteria outside of general opportunism.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Hacktivism
APT
ransomware
financial-gain
cyber-criminal
Middle East

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 31, 2025
Last Seen
Oct 11, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.