THREAT ACTOR
BQTLOCK_
DormantBQTLOCK is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of BQTLOCK, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 2
- 2025 9
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
yywhylvqeqynzik6ibocb53o2nat7lmzn5ynjpar3stndzcgmy6dkgid.onionBQTlock :: RaaS & Decryption Portal snapshot · 2026-04-03 20:17
Recent victims
The 50 most recent victims claimed by BQTLOCK. Total in the index: 11.
| Date listed | Victim | Description |
|---|---|---|
| 2026-04-03 | Metro Hospital USA | Primary Domain: metro.hospital (Internet Site - before it went down) … |
| 2026-01-01 | DGM | Website: dgm.co.il Data Size: 526 GB Payment Status: Unpaid - Pr… |
| 2025-12-27 | Morning Desert Safari | Website: morningdesertsafari.net Payment Status: Unpaid - Private … |
| 2025-12-27 | Arabian Desert Safari | Website: arabiandesertsafari.net Payment Status: Unpaid - Private … |
| 2025-12-27 | Dhow Cruise Dubai Harbour | Website: dhowcruisedubaiharbour.com Payment Status: Unpaid - Priva… |
| 2025-12-27 | Hatta Heritage Village | Website: hattaheritagevillage.com Payment Status: Unpaid - Private… |
| 2025-10-11 | Adore UAE | Domains: adoreuae.com www.adoreuae.com Active Since: 2017 Data S… |
| 2025-10-11 | EPS FUJ Private School UAE | Domains: epsfuj.com www.epsfuj.com Active Since: 2024 Data Size:… |
| 2025-08-09 | European Business Server Cluster | Domains: www.bizoneo.com www.bizosoft.eu meeting.wandsoft.com datapro… |
| 2025-07-31 | eFunda, Inc. | Domain: efunda.com (270+ subdomains) Active Since: 1999 Data Size: ~… |
| 2025-07-30 | USA Military Alumni Networks | Domains: isabrd.com, varsityo.com, letterwinner.com, whoglue.net, whog… |
CONFIRMED ATTACKS
BQTLock confirmed attacks: 4 verified incidents
Ransomnews has verified 4 BQTLock incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from October 2025 to December 2025. United Arab Emirates accounts for 4 of them (100%). The most affected sector is other, at 3 confirmed victims.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified BQTLock incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| December 2025 | Morning Desert Safari | Other | Dubai, United Arab Emirates | — | Unknown | Source |
| December 2025 | Dhow Cruise Dubai Harbour | Other | Dubai, United Arab Emirates | — | Unknown | Source |
| December 2025 | Hatta Heritage Village | Other | Dubai, United Arab Emirates | — | Unknown | Source |
| October 2025 | Adore UAE | Retail | Dubai, United Arab Emirates | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from BQTLock's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.