bqtlock
First seen July 31, 2025Active5 claimed victims
The claims below are reproduced as posted by bqtlock on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| EPS FUJ Private School UAE | October 11, 2025 | ransomware_live | — |
| Adore UAE | October 11, 2025 | ransomware_live | — |
| European Business Server Cluster | August 9, 2025 | ransomware_live | — |
| USA Military Alumni Networks | July 31, 2025 | ransomware_live | — |
| eFunda, Inc. | July 31, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).