bqtlock
INACTIVERansomware-as-a-Serviceransomware group
aka BaqiyatLock <br/>BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a double-extortion model. It employs AES-256 for file encryption, with keys secured by RSA-4096, appending the .BQTLOCK extension to encrypted files. Victims receive ransom notes such as READ_ME-NOW_*.txt, warning that failure to make contact within 48 hours doubles the ransom, and that decryption keys will be destroyed after seven days. The group offers tiered pricing "waves" with different XMR (Monero) amounts for quicker decryption—e.g., Wave 1 might cost 13 XMR, while Wave 3 could be 40 XMR. Targets include organizations such as U.S. military alumni networks and educational institutions.
Group Activity
Last 12 monthsVictims (5)
Adore UAE
adoreuae.com www.adoreuae.com
EPS FUJ Private School UAE
epsfuj.com www.epsfuj.com
European Business Server Cluster
www.bizoneo.com www.bizosoft.eum eeting.wandsoft.com dataprotectionact.ie bizoneo.com www.bizoneo.eu www.bizoneo-membership.eu www.tourguides.ie bizoneo-members...
eFunda, Inc.
efunda.com (270+ subdomains)
USA Military Alumni Networks
isabrd.com, varsityo.com, letterwinner.com, whoglue.net, whoglue.com, whoware.com, mail.usna87.com
Infrastructure
No sites tracked