Actor Profile

🏹 bqtlock — Ransomware

BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.

Classification

Ransomware

Leak-site victims

5
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (5)

VictimCountryPublishedDomain
Adore UAE AE 2025-10-11T20:28:01.448672+00:00 adoreuae.com
EPS FUJ Private School UAE AE 2025-10-11T20:27:35.043646+00:00 epsfuj.comw
European Business Server Cluster 2025-08-09T21:11:06.868100+00:00 bizoneo.com
eFunda, Inc. US 2025-07-31T19:16:20.624614+00:00 efunda.com
USA Military Alumni Networks US 2025-07-31T19:15:51.954031+00:00 usna87.com

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach bqtlock (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php