logo

GOLD BLADE Using Custom QWCrypt Locker that Allows Data Exfiltration and Ransomware Deployment

ID: 9410a598-db3a-5403-9549-ba207cab0fea

STIX ID: report--9410a598-db3a-5403-9549-ba207cab0fea

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GOLD BLADE has shifted to a hybrid espionage-and-extortion model, delivering multi-stage RedLoader infections via trusted recruitment platforms (fake PDF resumes and portal redirects), exfiltrating data with 7‑Zip over WebDAV/Cloudflare Workers, and selectively deploying a custom locker, QWCrypt, which appends .qwCrypt, supports hypervisor targeting, and is paired with an AV‑killing service and recovery disabling to maximize impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.