logo

BQTLock & GREENBLOOD Ransomware Attacking Organizations to Encrypt and Exfiltrate Data

ID: ec42282e-04f5-5d1b-b292-297a86b4d152

STIX ID: report--ec42282e-04f5-5d1b-b292-297a86b4d152

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Balaji N

...
...

**Executive Summary:** The report describes two emerging ransomware families—BQTLock, which prioritizes stealth and espionage by injecting a Remcos payload into explorer.exe, performing a UAC bypass via fodhelper.exe, establishing autorun persistence, and harvesting credentials/screens for extortion; and GREENBLOOD, a Go-based, fast-acting strain using ChaCha8 encryption, rapid artifact deletion, and a TOR leak site to maximize impact. Analysts observed both families in ANY.RUN sandboxes, highlighting behavioral IOCs and recommending behavioral/endpoint monitoring to detect pre-encryption indicators and prevent compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.