New post from #Bqtlock : Metro Hospital Usa
More at : https://www.ransomlook.io/group/Bqtlock #Ransomware
bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.

⚠️ New #RaaS alert: #BQTLock hides inside explorer.exe, bypasses UAC silently, and wipes its own launcher with a self-deleting script.

❗️ Healthcare & Finance at risk, but not just them. See how to detect and stop: https://any.run/malware-trends/bqtlock/?utm_source=mastodon&utm_medium=post&utm_campaign=bqtlock&utm_term=090326&utm_content=linktomtt

#cybersecurity

Sicarii redirige ses affiliés vers le RaaS BQTLock; exploitation de React2Shell (CVE-2025-55182)

Selon le Halcyon Ransomware Research Center, l’administrateur de Sicarii a appelé les opérateurs pro-palestiniens et pro-régime iranien à migrer vers Baqiyat 313 Locker (BQTLock), faute de capacité à traiter l’afflux d’affiliés. BQTLock ouvre un accès RaaS gratuit via Telegram pour des actions idéologiques pro-palestiniennes, tandis que Sicarii annonce se recentrer sur l’influence hacktiviste. Analyse des acteurs et cibles: BQTLock, divulgué publiquement en juillet 2025, serait développé par les hacktivistes pro-palestiniens Liwaa Mohammad et Karim Fayad (ZeroDayX/ZeroDayX1), sous l’ombrelle Cyber Islamic Resistance. BQTLock et Sicarii sont des RaaS distincts; Sicarii redirige désormais ses affiliés vers BQTLock pour des attaques motivées idéologiquement. BQTLock pratique la double extorsion et a publié des données d’entités des secteurs hôtellerie et éducation aux Émirats arabes unis, États-Unis et Israël. Des messages récents sur les canaux Cyber Islamic Resistance montrent un intérêt pour des cibles d’infrastructures critiques et militaires, incluant des assertions de fuites d’une base de données militaire israélienne et d’une liste d’agents du Mossad.

CyberVeille

⚠️ New ransomware #BQTLock & #GREENBLOOD are actively targeting businesses.

Stealth, rapid encryption, and leak-site pressure leave SOC teams little time to react.

Check out detailed analysis and an actionable plan to detect them before downtime ⬇️
https://any.run/cybersecurity-blog/emerging-ransomware-bqtlock-greenblood/?utm_source=mastodon&utm_medium=post&utm_campaign=emerging_ransomware&utm_term=110226&utm_content=linktoblog

#cybersecurity #infosec

Emerging Ransomware Threats: BQTLock and GREENBLOOD Analysis

Explore how BQTLock and GREENBLOOD ransomware operate, why they threaten businesses, and how ANY.RUN helps detect attacks earlier.

ANY.RUN's Cybersecurity Blog

⚠️ #BQTLock ransomware uses #Remcos injected into explorer.exe to hide inside normal system activity. In the #ANYRUN Sandbox, behavioral analysis and file system monitoring exposed a UAC bypass via fodhelper.exe, followed by persistence through autorun mechanisms with elevated privileges.

👾 Once elevated, the malware moves into data theft and screen capture. See the full execution chain and collect #IOCs to speed up detection and cut response time: https://app.any.run/tasks/90be5f16-fdde-4aca-9482-86e2aa43fba0/?utm_source=mastoodon&utm_medium=post&utm_campaign=bqtlock_case&utm_term=300126&utm_content=linktoservice

👨‍💻 Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/features/?utm_source=mastodon&utm_medium=post&utm_campaign=bqtlock_case&utm_term=300126&utm_content=linktosandboxlanding

#cybersecurity #infosec

bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.

New post from #Bqtlock : Morning Desert Safari
More at : https://www.ransomlook.io/group/Bqtlock #Ransomware
bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.

New post from #Bqtlock : Arabian Desert Safari
More at : https://www.ransomlook.io/group/Bqtlock #Ransomware
bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.

New post from #Bqtlock : Hatta Heritage Village
More at : https://www.ransomlook.io/group/Bqtlock #Ransomware
bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.

New post from #Bqtlock : Dhow Cruise Dubai Harbour
More at : https://www.ransomlook.io/group/Bqtlock #Ransomware
bqtlock details

Open, searchable ransomware group intelligence with live stats, posts and an API.