https://x.com/zerodayx1
BQTLock
BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names.
Profile source: Mallory opens in a new tabBQTLock
Family profile
BQTLock is a ransomware/Ransomware-as-a-Service (RaaS) operation referenced as a new ransomware strain active in 2025 and reported to have multiple variants and names. The malware is associated with the pro-Palestinian hacktivist group zerodayx1, which launched BQTLock as a RaaS offering. Reporting explicitly describes this as a pivot combining ideological messaging with subscription-based extortion, reflecting a blend of hacktivism and financially motivated ransomware activity. Mentioned coverage includes research on BQTLOCK ransomware and its variants, and analysis comparing BQTLock with another new strain, GREENBLOOD. The available content does not provide technical details on encryption routines, specific infection vectors, targeted operating systems, victimology, or concrete indicators of compromise beyond the association with zerodayx1 and its positioning as a ransomware/RaaS operation.
Operational record
Published indicators
Telegram
5 totalhttps://t.me/BQTlockhttps://t.me/liwaamohammadhttps://t.me/ZeroDayX1https://t.me/BQTlock_raashttps://t.me/Fuch0u
Xmr
1 total89RQN2EUmiX6vL7nTv3viqUAgbDpN4ab329zPCEgbceQJuS233uye4eXtYk3MXAtVoKNMmzgVrxXphLZbJPtearY7QVuApr
Exploited software
Vulnerabilities linked to BQTLock
1 CVEsMITRE ATT&CK