BQTLOCK Ransomware Attacking Windows Users Via Telegram to Encrypt Files and Delete Backup
## Cybersecurity: BQTLOCK Ransomware Analysis
Cybersecurity: BQTLOCK Ransomware Analysis
Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK. This ransomware targets Windows users and is distributed via Telegram channels and dark web forums. Since mid-July, affiliates have been using a ZIP archive containing a malicious executable to encrypt files, append a custom “.bqtlock” extension, and delete system backups.
BQTLOCK uses several anti-analysis measures, including string obfuscation and debugger checks. The malware encrypts files under 50 MB using AES-256 encryption and protects the AES key with RSA-4096 encryption. Upon execution, it encrypts files while excluding Windows system directories.
Victims receive a ransom note demanding payment in Monero within 48 hours. If no contact is made, the ransom doubles, and decryption keys are permanently deleted. Encrypted files are renamed with the “.bqtlock” extension, and a ransom note is placed in each directory.
BQTLOCK gathers system information, including host name, user name, hardware ID, and public IP address. This data is exfiltrated through a Discord webhook. The malware attempts privilege escalation using several UAC bypass techniques and creates a local administrator account named “BQTLockAdmin.” It also terminates antivirus and backup services by targeting specific processes.
Security researchers have identified a new Ransomware-as-a-Service (RaaS) strain named BQTLOCK.
The BQTLOCK RaaS offers three subscription tiers: Starter, Professional, and Enterprise. These tiers allow affiliates to configure ransom note details, wallpaper images, icons, and file extensions. Affiliates can customize payloads using a ransomware builder interface without coding experience.
The latest version includes enhanced anti-debug checks, code obfuscation, UAC bypass methods, and modules for stealing credentials from popular browsers. The malware uses WMI queries to gather hardware details, clears event logs, and copies itself for lateral movement.
Organizations and individuals should maintain updated antivirus defenses and robust backup strategies, preferably offline or immutable. Monitoring for suspicious scheduled tasks and new administrative accounts is also recommended. Solutions like K7 Total Security can provide additional protection against emerging threats like BQTLOCK.
Based on reporting by GBHackers.
