Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 22, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names.
Profile source: Mallory opens in a new tabBQTLock
BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names. The malware is associated with the pro-Palestinian hacktivist group zerodayx1, which launched BQTLock as a RaaS offering. Reporting explicitly describes this as a pivot combining ideological messaging with subscription-based extortion, reflecting a blend of hacktivism and financially motivated ransomware activity. Mentioned coverage includes research on BQTLOCK ransomware and its variants, and analysis comparing BQTLock with another new strain, GREENBLOOD. The available content does not provide technical details on encryption routines, specific infection vectors, targeted operating systems, victimology, or concrete indicators of compromise beyond the association with zerodayx1 and its positioning as a ransomware/RaaS operation.
C2 tracking
Derp observations, rolling seven-day window
Samples
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.