BQTLOCK Ransomware Attacking Windows Users Via Telegram to Encrypt Files and Delete Backup
Security researchers have identified a new Ransomware-as-a-Service (RaaS) called BQTLOCK. This malware is being distributed through Telegram channels and dark web forums, primarily targeting Windows users. Since mid-July, the ransomware has been…
Security researchers have identified a new Ransomware-as-a-Service (RaaS) called BQTLOCK. This malware is being distributed through Telegram channels and dark web forums, primarily targeting Windows users. Since mid-July, the ransomware has been distributed via a ZIP archive containing a malicious executable that encrypts a variety of file types, appends a “.bqtlock” extension, and deletes system backups to hinder recovery.
BQTLOCK employs multiple techniques to avoid detection. These include string obfuscation, debugger checks, and virtual machine evasion stubs. Upon execution, the file named Update.exe encrypts files under 50 MB using AES-256 for the file content and RSA-4096 for securing the AES key and initialization vector.
The ransomware generates a note demanding payment in Monero within 48 hours, threatening to double the fee and erase decryption keys permanently if no contact is made.
Once activated, BQTLOCK performs reconnaissance and privilege escalation. It collects system information such as host name, user name, hardware ID, and public IP address, exfiltrating the data via a Discord webhook. The ransomware attempts to gain elevated privileges and creates a new local administrator account named “BQTLockAdmin.”
Security researchers have identified a new Ransomware-as-a-Service (RaaS) called BQTLOCK.
Furthermore, it terminates antivirus and backup services, registers a scheduled task for persistence, modifies file icons, and sets a custom wallpaper.
BQTLOCK offers three subscription tiers: Starter, Professional, and Enterprise. These tiers allow for customization of ransom note details, wallpaper image, icon, file extensions, and optional anti-analysis features. Affiliates can configure these settings via a ransomware builder interface without needing coding skills.
The latest version includes new anti-debug checks, enhanced code obfuscation, UAC bypass methods, and credential-stealing modules targeting browsers like Chrome, Firefox, Edge, Opera, and Brave.
Organizations and individuals should ensure their antivirus defenses are current, employ robust backup strategies (preferably offline or immutable), and monitor for suspicious scheduled tasks and new administrative accounts.
For further protection against threats like BQTLOCK, solutions such as K7 Total Security can be considered.
Based on reporting by GBHackers.
