BQTLock & GREENBLOOD Ransomware Attacking Organizations to Encrypt and Exfiltrate Data
ID: ec42282e-04f5-5d1b-b292-297a86b4d152
STIX ID: report--ec42282e-04f5-5d1b-b292-297a86b4d152
Feed Name: cybersecurityNews.com
**Executive Summary:** The report describes two emerging ransomware families—BQTLock, which prioritizes stealth and espionage by injecting a Remcos payload into explorer.exe, performing a UAC bypass via fodhelper.exe, establishing autorun persistence, and harvesting credentials/screens for extortion; and GREENBLOOD, a Go-based, fast-acting strain using ChaCha8 encryption, rapid artifact deletion, and a TOR leak site to maximize impact. Analysts observed both families in ANY.RUN sandboxes, highlighting behavioral IOCs and recommending behavioral/endpoint monitoring to detect pre-encryption indicators and prevent compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
