Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
137
Global rank
75 infographic chevron month
Month rank
95 infographic chevron week
Week rank
0
IOCs

BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.

Ransomware
Type
Unknown
Origin
15 July, 2025
First seen
14 September, 2026
Last seen
Also known as
baqiyatlock

How to analyze BQTLock with ANY.RUN

Type
Unknown
Origin
15 July, 2025
First seen
14 September, 2026
Last seen

IOCs

IP addresses
135.233.45.223
2.23.246.9
20.190.160.14
2.23.246.101
74.178.76.128
57.153.246.3
48.192.1.64
48.209.6.48
48.209.138.168
104.16.185.241
172.211.123.250
95.100.102.101
23.216.77.36
23.216.77.9
20.165.94.54
23.216.77.7
172.66.2.5
23.194.190.171
2.16.168.46
150.171.28.11
Hashes
2d711642b726b04401627ca9fbac32f5c8530fb1903cc4db02258717921a4881
f5d711c13530a1aa051e583ba4e78263326431fbce7198998178b5a0fb14d4d9
1b3d6e1878afbd806dc16b15bf36ea113429b64c7597236f81c91406cf727b1c
28825ea8245e6bcd88c3b4d744e07712f905d316d7005845629b4f98b7d533b9
3eca71e8896d337837dd4711678fe3326746ed34ec9a2c10e8557e2e6d873b4d
39b69807f2b9a13cb5bc054a680e00b8d7fde30cd258286398d0cfe664aa7515
f3ed5ff2cba8ef2e326a8eca80976684fa2889f15c12f6d75b59d2909d49faa9
f974f6c38235684981f1f3fd90809a3de9ce03d2ba596126c6db2b1450d358e5
60395a6b81c54ca819c21e7699012ed3b0034c1a65aa34dbbaa1c8edcbc2261d
bb4ae22cd40bad2d020c38e093f9ce65ae90a1fc114433c77ff6ceda52af2217
a47837c3db463e0825ca36f6037f486bf9d4ced7853a4e75d09534e1d662f964
8a6d5a81721894f261e339c8f2cf6c96dbd50f71d014d87043211f346d1c9d71
61908bb8ad8fa04853660bf199cd05d0bcd5cb5c935c52768381d33407e5803d
6620b7cadd53920b0c26a57a278723672ac404353719edecd4c3fb5be22047b5
6d8cd0cd087bb4996804df562e182c766f48310d4a8ee350f253e018c5e66207
0190fe27e233a7b5ad89761b862f2674d41671d1df85b4561f2963a68819d638
c9f59d30f205c8af7bb282cc067b862439ee250808116e99a13306a76668d489
e16f6e938d02661c9080eaf8d965484effc285a415642cba9a9a8a4277f7aac8
06a80881104ac3553bbfed2e117c739c9f088ff5f7f941444fe08f31abdf65f8
4b115b4ff2df6e965382179986959d8c6d60af63e0cca32a7c7574e5a29b7dca
Domains
watson.events.data.microsoft.com
google.com
go.microsoft.com
activation-v2.sls.microsoft.com
crl.microsoft.com
www.microsoft.com
slscr.update.microsoft.com
ecs.office.com
icanhazip.com
self.events.data.microsoft.com
settings-win.data.microsoft.com
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
login.live.com
ocsp.digicert.com
nexusrules.officeapps.live.com
edge.microsoft.com
fs.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
edge-consumer-static.azureedge.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://icanhazip.com/
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://watson.events.data.microsoft.com/telemetry.request
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wrqokbln_zapxyk6y795pxvp_r4kriha-9tedj_7jvm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 131
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 2027
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5830
comments 0

BQTLock RaaS: The Ransomware That Encrypts Files, Steals Credentials, and Hides Inside Windows

Key Takeaways

  1. BQTLock is a RaaS that first appeared in July 2025, linked to the threat actor ZerodayX and the hacktivist group Liwaa Mohammed.
  2. It uses a dual-threat payload: AES-256/RSA-4096 encryption for ransom extortion, combined with browser credential theft and Windows Credential Manager harvesting. Even organizations with good backups face data breach exposure.
  3. BQTLock's evasion capabilities — process hollowing into explorer.exe, UAC bypass via fodhelper/eventvwr/CMSTP, IsDebuggerPresent anti-debug, VM detection, and Sleep-based sandbox evasion — make it unusually difficult for traditional security tools to detect and analyze.
  4. The malware creates persistent backdoor access via a hidden administrator account (BQTLockAdmin) and a scheduled task disguised as a legitimate Windows maintenance process, meaning remediation must include thorough forensic verification, not just antivirus removal.
  5. Healthcare, financial services, and government sectors face the highest risk due to the sensitivity of their data, regulatory penalties, and the high operational impact of downtime.
  6. ANY.RUN’s Threat Intelligence Lookup helps investigators quickly identify malicious indicators and infrastructure linked to ransomware campaigns.

destinationIP:"92.113.146.56".

BQTLock domain in TI Lookup BQTLock domain with context data and malware analyses

  1. ANY.RUN's Interactive Sandbox allows SOC analysts and MSSPs to safely execute suspicious files in an isolated environment and observe BQTLock's full attack chain in real time providing the behavioral evidence needed to build precise detection rules and confidently scope incidents.

View BQTLock sample analysis

BQTLock malware analysis in Interactive Sandbox BQTLock fresh sample analysis in Interactive Sandbox

What is BQTLock Malware?

BQTLock is a sophisticated ransomware strain that emerged in mid-July 2025, operating under a full Ransomware-as-a-Service (RaaS) model. Also known as BaqiyatLock, it combines powerful hybrid encryption, advanced anti-analysis evasion, credential theft, and aggressive double-extortion tactics into a single, commercially distributed package. Linked to the threat actor known as ZerodayX (the alleged leader of the pro-Palestinian hacktivist group Liwaa Mohammed) BQTLock has attracted significant attention from security researchers for the speed of its development, the sophistication of its evasion mechanisms, and its openly commercial approach to cybercrime.

BQTLock represents a new generation of ransomware built for commercial scalability rather than targeted deployment by a single group. From its first appearance in July 2025, the malware has evolved rapidly. Researchers observed a significantly enhanced variant released on August 5, 2025, just weeks after the original, incorporating credential harvesting and expanded UAC bypass techniques.

The malware uses a hybrid encryption scheme combining AES-256 symmetric encryption with RSA-4096 asymmetric encryption. This pairing ensures that even if the symmetric key used to encrypt files is discovered, it cannot be decrypted without the attacker's private RSA key making recovery without paying the ransom effectively impossible absent a cryptographic flaw or law enforcement action. All encrypted files are appended with the .bqtlock extension, and victims are left with a ransom note.

BQTLock's ransom demands are structured as tiered "waves," priced in Monero (XMR) for maximum anonymity. Depending on the wave assignment found in the ransom note, victims may be charged between 13 XMR and 80 XMR (roughly $3,600 to over $22,000 at current exchange rates), with faster decryption processing tied to higher payment tiers. This gamified pricing structure is designed to maximize psychological pressure and speed of payment.

In addition to file encryption, BQTLock includes a mature information-stealing module. It harvests credentials stored in major browsers — Chrome, Firefox, Edge, Opera, and Brave — and accesses the Windows Credential Manager to extract system-level credentials. Stolen data is exfiltrated via Discord webhooks and Telegram channels.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How BQTLock Threatens Businesses and Organizations

BQTLock poses a multi-dimensional threat to organizations. Its dangers extend well beyond file encryption, touching operational continuity, data confidentiality, regulatory standing, and reputational integrity simultaneously.

  • Operational Disruption. Organizations that rely on real-time data access — hospitals, manufacturers, financial institutions — can find themselves operationally paralyzed within minutes. The 48-hour payment deadline and seven-day key destruction threat inject extreme urgency into crisis response, forcing organizations to make high-stakes decisions under pressure.

  • Data Theft and Double Extortion. Credentials extracted from browsers and the Windows Credential Manager can enable follow-on attacks — account takeovers, privilege escalation across cloud services, lateral movement into connected partner networks — that extend the damage of a single infection far beyond the initially compromised environment.

  • Persistence and Backdoor Access. BQTLock creates a hidden administrator account named BQTLockAdmin and establishes a scheduled task disguised as "Microsoft\Windows\Maintenance\SystemHealthCheck" that persists across reboots. This means that even after an organization believes it has remediated an infection, the threat actor may retain access to the environment.

  • Financial Impact. Beyond the ransom itself, organizations face the costs of incident response, forensic investigation, potential regulatory fines (especially under GDPR, HIPAA, or similar frameworks), and reputational damage.

Victimology: Which Industries Are Most at Risk?

BQTLock's RaaS model means that targeting decisions are partially decentralized. Affiliates choose their own victims, often guided by opportunism, data value, or ideological motivation. The hacktivist associations of its core developer suggest that geopolitically sensitive targets may be disproportionately represented. However, certain structural factors make some sectors especially vulnerable regardless of attacker intent.

Is your business at risk? Most targeted sectors Is your business at risk? Most targeted sectors

BQTLock's credential-harvesting capability introduces a second-order victimology: organizations whose credentials are stolen may find themselves targeted in subsequent, unrelated attacks by actors who purchase stolen data. Supply chain partners, cloud service providers, and third-party vendors connected to primary victims should also consider themselves at elevated risk following any confirmed BQTLock incident in their ecosystem.

How Can Businesses Proactively Protect Against BQTLock

ANY.RUN's TI Lookup gives security analysts instant access to a searchable database populated by real malware executions from 15,000 organizations worldwide. When a suspicious file hash, IP address, domain, or registry key appears in an alert, analysts can query TI Lookup and receive verdict and context within seconds, including whether the indicator has been associated with BQTLock activity. This eliminates hours of manual OSINT research and gives SOC teams the evidence they need to act decisively on high-priority incidents.

sha256:"4437ab9c5db3c5ebb9235b4adade504153fa39ca5774ac8c6145a0b7c97a97eb"

File hash linked to BQTLock samples File hash linked to BQTLock samples

ANY.RUN's TI Feeds deliver a continuous stream of verified malicious network indicators extracted from live sandbox executions in STIX/TAXII format. Security teams can integrate these feeds directly into their SIEM, EDR, NGFW, IDS/IPS, or TIP platforms without custom development. As BQTLock evolves and new variants introduce new C2 infrastructure, TI Feeds ensure that downstream blocking rules are updated in near-real time — before most threat intelligence reports describing the new variant have even been written.

TI Feeds benefits and integration TI Feeds: benefits, data sources, integration options

Other Defensive Measures

  • Implement offline, immutable backups on a regular schedule and test restoration procedures before an incident occurs.

  • Deploy endpoint detection and response (EDR) tools configured to flag process hollowing, unusual scheduled task creation, and new local administrator account creation — all behaviors exhibited by BQTLock.

  • Enforce application whitelisting to prevent the execution of unsigned or unexpected executables, particularly those delivered via ZIP archives.

  • Block execution of scripts and executables from temporary directories (e.g., C:\Windows\Temp) where BQTLock stages its payload.

  • Apply the principle of least privilege to limit the blast radius of any credential compromise; disable or restrict Windows Credential Manager storage for sensitive accounts.

  • Enable and monitor Windows Event Logs for UAC bypass attempts, particularly involving fodhelper.exe, eventvwr.exe, and CMSTP.exe.

  • Conduct phishing awareness training with emphasis on ZIP attachment risks and the dangers of executing files named generically (e.g., "Update.exe").

  • Use ANY.RUN's Sandbox to safely detonate suspicious files and observe full behavioral chains.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

How BQTLock Gets in the System and Functions

Common entry vectors include:

BQTLock initial access methods BQTLock initial access methods

Execution and Privilege Escalation

Upon execution, BQTLock performs an immediate anti-analysis check using the IsDebuggerPresent() API and creates a global mutex to prevent duplicate execution. If no analysis environment is detected, it proceeds to escalate privileges through multiple UAC bypass techniques: abusing CMSTP.exe with crafted .inf files, and manipulating registry keys associated with fodhelper.exe and eventvwr.exe auto-elevation behaviors. These methods allow the malware to acquire administrative privileges without triggering visible UAC prompts to the user.

Lateral Movement

BQTLock checks the USB bus for connected removable media, enabling it to spread to other systems via external drives. It also enumerates shared network resources, potentially enabling encryption of mapped network drives visible from the initially compromised host. The credentials harvested from browsers and the Windows Credential Manager can be used to authenticate to additional systems within the network, supporting broader lateral movement.

Persistence

The malware establishes persistence through a scheduled task named "Microsoft\Windows\Maintenance\SystemHealthCheck", configured to execute at user logon with elevated privileges. It also creates a hidden administrator account (BQTLockAdmin) to maintain backdoor access. A self-deleting .bat script is deployed to remove the original executable and reduce forensic artifacts after the payload has completed its initial execution phase.

Process Injection and Code Hiding

BQTLock uses process hollowing targeting explorer.exe — a technique in which the malware injects its code into a legitimate Windows process, running malicious operations under the cover of a trusted system binary. This significantly reduces the likelihood of detection by security tools that whitelist known Windows processes.

Credential Theft

Credential harvesting targets browser data stores for Chrome, Firefox, Edge, Opera, and Brave, as well as the Windows Credential Manager. Credentials are temporarily written to C:\Windows\Temp\bqt_passwords.txt before exfiltration. Screenshots and system metadata are sent alongside credentials via Telegram bot tokens and Discord webhooks hardcoded in the malware's configuration.

Encryption Routine

The encryption engine uses AES-256 for the bulk encryption of file contents (fast, symmetric) and RSA-4096 to encrypt the AES key (making it irrecoverable without the attacker's private key). Files of all types are targeted; each receives the .bqtlock extension. A completion notification is sent to the attacker's Telegram channel, confirming successful encryption of the victim's environment.

Ransom Demand

The ransom note dropped to the victim's system includes a unique victim ID that maps to a specific payment wave tier, a Telegram contact link, and explicit warnings against using third-party recovery tools or backups. The 48-hour doubling deadline and seven-day key deletion threat are enforced through the RaaS platform's real-time infection monitoring dashboard.

Sandbox Analysis of BQTLock Sample

See full execution chain of BQTLock

ANY.RUN sandbox revealing BQTLock behavior in real time ANY.RUN sandbox revealing BQTLock behavior in real time

When launched, BQTLock performs a UAC bypass using fodhelper. When fodhelper.exe starts, it accesses a specific registry key and executes the command specified there. Because fodhelper.exe has the autoElevate flag, the operating system automatically elevates the privileges of the launched component. This allows the malware to obtain administrator privileges without displaying a UAC prompt to the user, resulting in the program running with admin rights.

Upon-launch BQTLock activity Upon-launch BQTLock activity

A distinctive feature of this campaign is the use of an infection chain involving Remcos, which is injected into the Windows Explorer process.

Remcos injected in Explorer Remcos injected in Explorer

To ensure persistence in the system, the malware creates a task in the Windows Task Scheduler.

BQTLock’s Scheduler task BQTLock’s Scheduler task

During execution, BQTLock modifies the system registry. This modification forces Windows Explorer to refresh its contents, allowing the victim to notice changes in the file system more quickly.

HTTP requests reveal connections to the service http://icanhazip[.]com/, which is used to determine the victim machine’s public IP address.

The malware also attempts to communicate with several command-and-control (C2) servers, including connection attempts to Discord and Telegram, which fail. A successful connection is established with http://92[.]113[.]146[.]56/api[.]php, followed by further communication with this endpoint.

BQTLock’s connection requests BQTLock’s connection requests

Files are encrypted with the .bqtlock extension, and a ransom note named README_TO_DECRYPT.txt is dropped. The malware also changes the desktop wallpaper.

BQTLock’s ransom note BQTLock’s ransom note

These parameters, including the C2 infrastructure, can be modified in the ransomware builder, so they may vary between different samples.

In addition to its primary functionality of file encryption, the malware includes data theft capabilities, such as taking screenshots or extracting stored passwords.

BQTLock’s harvesting sensitive data BQTLock’s harvesting sensitive data

Conclusion

BQTLock illustrates how modern ransomware operations have evolved into commercialized cybercrime platforms.

Its combination of ransomware-as-a-service infrastructure, credential theft, advanced evasion techniques, and double extortion tactics makes it a serious threat for organizations of all sizes.

Because ransomware campaigns often rely on recognizable infrastructure and behavioral patterns, proactive threat intelligence and behavioral analysis are essential tools for identifying attacks before they cause operational damage.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More
Caminho Loader screenshot
Caminho Loader
caminho caminholoader
Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms. Active since March 2025, it has delivered a variety of malware and infostealers to victims within multiple industries across South America, Africa, and Eastern Europe.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More