BQTLOCK Ransomware Attacking Windows Users Via Telegram to Encrypt Files and Delete Backup
Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK, targeting Windows users via Telegram channels and dark web forums. Since mid-July, affiliates have been distributing a ZIP archive containing a malicious…
Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK, targeting Windows users via Telegram channels and dark web forums. Since mid-July, affiliates have been distributing a ZIP archive containing a malicious executable that encrypts various file types, appends a custom ".bqtlock" extension, and deletes system backups to prevent recovery.
BQTLOCK employs multiple anti-analysis techniques to avoid detection, including string obfuscation, debugger checks, and virtual machine evasion stubs. Once executed, the file "Update.exe" encrypts files under 50 MB using AES-256 for file content and RSA-4096 to secure the AES key and initialization vector.
Victims receive a ransom note demanding payment in Monero within 48 hours, with threats of doubling the fee and permanently erasing decryption keys if no contact is made. Encrypted files are renamed with the ".bqtlock" extension, and a ransom note is placed in each directory.
Upon execution, BQTLOCK performs reconnaissance and privilege escalation steps, gathering system information and exfiltrating data through a Discord webhook. The malware attempts to enable SeDebugPrivilege and uses UAC bypass methods to gain elevated privileges. It creates a local administrator account named "BQTLockAdmin" and injects code into explorer.exe for stealth.
BQTLOCK employs multiple anti-analysis techniques to avoid detection, including string obfuscation, debugger checks, and virtual machine evasion stubs.
To ensure persistence, it registers a scheduled task, sets a custom wallpaper, and modifies file icons via registry keys. The malware also terminates antivirus and backup services by enumerating and forcibly terminating targeted processes.
The BQTLOCK RaaS offers three subscription tiers—Starter, Professional, and Enterprise—with configurable ransom note details and optional anti-analysis features. Affiliates can adjust settings in the ransomware builder interface without coding experience.
A version 4 builder released in August included new anti-debug checks, enhanced code obfuscation, UAC bypass methods, and credential-stealing modules targeting passwords from major browsers. This variant uses WMI queries to collect hardware details and drops a script for self-deletion and lateral movement.
Despite claims of being fully undetectable, analysis revealed a corrupted ISO sample and limited VirusTotal submissions, suggesting the claims are misleading. The ransomware attempts to establish persistent administrative access by creating a new local user with administrative rights.
With ransomware attacks increasing, organizations and individuals should maintain updated antivirus defenses, employ robust backup strategies, and monitor for suspicious scheduled tasks and new administrative accounts.
Based on reporting by GBHackers.
