HomeSecurityBQTLOCK: A New Ransomware-as-a-Service Threat

BQTLOCK: A New Ransomware-as-a-Service Threat

A new sophisticated ransomware called BQTLOCK has appeared on the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS). Thus, various cybercriminals can access the malware with its advanced encryption capabilities.

BQTLOCK ransomware

The malware, linked to 'ZerodayX', the alleged leader of the pro-Palestinian hacktivists group Liwaa Mohammed, represents a worrying development in ransomware distribution and commercialization strategies.

BQTLOCK uses a subscription model, offering three levels of service: Starter, Professional, and Enterprise packages, each of which provides customizable features, such as ransom note personalization, wallpaper modification, file extensions , and configurable anti-fraud options.

See also: Colt: Warlock ransomware group sells customer data

BQTLOCK Ransomware: Attacks

The ransomware demands from victims 13 to 40 Monero (XMR) tokens, equivalent to $3,600 to $10,000. After 48 hours, the ransom is doubled and the hackers threaten to permanently delete data (stolen from the target systems) after seven days.

K7 Security Labs analysts identified the malware's sophisticated architecture, which combines traditional double blackmail tactics with modern analysis evasion techniques.

The ransomware encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, appending the .bqtlock to compromised files, while simultaneously extracting sensitive data via Discord webhooks for command-and-control communications.

The malware's distribution mechanism includes ZIP files containing the main executable file Update.exe along with 20 supporting DLL files.

Upon execution, BQTLOCK performs extensive system reconnaissance, collecting computer names, IP addresses, hardware identifiers, and disk space information before establishing persistence and starting the encryption process.

An updated variant discovered on August 5, 2025, demonstrates the threat actors’ commitment to continued development, incorporating enhanced credential theft capabilities that target popular browsers such as Chrome, Firefox, Edge, Opera, and Brave. This development significantly expands the malware’s data collection capabilities beyond file encryption.

See also: Dire Wolf ransomware targets tech companies

BQTLOCK: A New Ransomware-as-a-Service Threat

How does BQTLOCK stand out?

BQTLOCK ransomware implements a multi-layered approach to avoid detection and persist in the system, which differentiates it from conventional ransomware families.

The malware initiates the evasion sequence using the IsDebuggerPresent() to detect active debugging environments, immediately terminating execution if analysis tools are detected. Additionally, it creates a global mutex named “Global\{00A0B0C0-D0E0-F000-1000-200030004000}” to prevent multiple instances from running concurrently.

The ransomware achieves privilege escalation by enabling SeDebugPrivilege using the OpenProcessToken and AdjustTokenPrivileges APIs . It also uses sophisticated process hollowing techniques that target explorer.exe. This approach allows BQTLOCK to inject malicious code into legitimate system processes, effectively masking its presence and making it difficult for security monitoring tools to detect .

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

To maintain permanent access, the malware creates a scheduled task that appears as “Microsoft\Windows\Maintenance\SystemHealthCheck”, exploiting the legitimate Windows maintenance nomenclature. At the same time, it creates a backdoor administrator account named “BQTLockAdmin” and password “Password123!”, ensuring continued access even after the initial detection of the breach.

See also: The Evolution of Ransomware and Attackers' New Tools

The updated variant introduces multiple UAC bypass techniques, including abuse of CMSTP.exe with crafted .inf files and registry manipulation targeting the auto-elevation features fodhelper.exe and eventvwr.exe. These methods allow the malware to run with elevated privileges without triggering User Account Control notifications, significantly reducing the likelihood of user intervention during the attack.

BQTLOCK: A New Ransomware-as-a-Service Threat

Ransomware protection

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS