🏹 bqtlock — Ransomware
BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.
Classification
Ransomware
Leak-site victims
5
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
—
ATT&CK
Tracked
Yes
Ransomware.live
🔥 Leak-Site Victims (5)
| Victim | Country | Published | Domain |
|---|---|---|---|
| Adore UAE | AE | 2025-10-11T20:28:01.448672+00:00 | adoreuae.com |
| EPS FUJ Private School UAE | AE | 2025-10-11T20:27:35.043646+00:00 | epsfuj.comw |
| European Business Server Cluster | 2025-08-09T21:11:06.868100+00:00 | bizoneo.com | |
| eFunda, Inc. | US | 2025-07-31T19:16:20.624614+00:00 | efunda.com |
| USA Military Alumni Networks | US | 2025-07-31T19:15:51.954031+00:00 | usna87.com |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
📁 Case Management
🏹 Campaigns & malware
🏹 Add to case
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron