Skip to content

BQTLock

BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names.

Profile source: Mallory opens in a new tab

BQTLock

Family profile

BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names. The malware is associated with the pro-Palestinian hacktivist group zerodayx1, which launched BQTLock as a RaaS offering. Reporting explicitly describes this as a pivot combining ideological messaging with subscription-based extortion, reflecting a blend of hacktivism and financially motivated ransomware activity. Mentioned coverage includes research on BQTLOCK ransomware and its variants, and analysis comparing BQTLock with another new strain, GREENBLOOD. The available content does not provide technical details on encryption routines, specific infection vectors, targeted operating systems, victimology, or concrete indicators of compromise beyond the association with zerodayx1 and its positioning as a ransomware/RaaS operation.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 22, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • DK1

Leading providers

  • Webdock.io ApS1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to BQTLock

1 CVEs

MITRE ATT&CK

BQTLock in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.