Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

BQTLOCK Ransomware Attacking Windows Users Via Telegram to Encrypt Files and Delete Backup

Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK, targeting Windows users via Telegram channels and dark web forums. Since mid-July, affiliates have been distributing a ZIP archive containing a malicious…

Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK, targeting Windows users via Telegram channels and dark web forums. Since mid-July, affiliates have been distributing a ZIP archive containing a malicious executable that encrypts various file types, appends a custom ".bqtlock" extension, and deletes system backups to prevent recovery.

BQTLOCK employs multiple anti-analysis techniques to avoid detection, including string obfuscation, debugger checks, and virtual machine evasion stubs. Once executed, the file "Update.exe" encrypts files under 50 MB using AES-256 for file content and RSA-4096 to secure the AES key and initialization vector.

Victims receive a ransom note demanding payment in Monero within 48 hours, with threats of doubling the fee and permanently erasing decryption keys if no contact is made. Encrypted files are renamed with the ".bqtlock" extension, and a ransom note is placed in each directory.

Upon execution, BQTLOCK performs reconnaissance and privilege escalation steps, gathering system information and exfiltrating data through a Discord webhook. The malware attempts to enable SeDebugPrivilege and uses UAC bypass methods to gain elevated privileges. It creates a local administrator account named "BQTLockAdmin" and injects code into explorer.exe for stealth.

BQTLOCK employs multiple anti-analysis techniques to avoid detection, including string obfuscation, debugger checks, and virtual machine evasion stubs.
Noah Redmond · Thehackingpost

To ensure persistence, it registers a scheduled task, sets a custom wallpaper, and modifies file icons via registry keys. The malware also terminates antivirus and backup services by enumerating and forcibly terminating targeted processes.

The BQTLOCK RaaS offers three subscription tiers—Starter, Professional, and Enterprise—with configurable ransom note details and optional anti-analysis features. Affiliates can adjust settings in the ransomware builder interface without coding experience.

A version 4 builder released in August included new anti-debug checks, enhanced code obfuscation, UAC bypass methods, and credential-stealing modules targeting passwords from major browsers. This variant uses WMI queries to collect hardware details and drops a script for self-deletion and lateral movement.

Advertisement

Despite claims of being fully undetectable, analysis revealed a corrupted ISO sample and limited VirusTotal submissions, suggesting the claims are misleading. The ransomware attempts to establish persistent administrative access by creating a new local user with administrative rights.

With ransomware attacks increasing, organizations and individuals should maintain updated antivirus defenses, employ robust backup strategies, and monitor for suspicious scheduled tasks and new administrative accounts.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories