PULSE NAME
BQTLock, Thread-Hijack Phishing, and MFA Bypass Evolution
WHITE PetrP.73 2026-03-08 Modified: 2026-04-07
5
IOCs
LOW VOLUME
In February 2026, the cyber threat landscape experienced significant evolution with the emergence of new ransomware and remote access trojans (RATs), as well as enhanced phishing techniques. Two noteworthy ransomware families, GREENBLOOD and BQTLock, were identified for their destructive capabilities. GREENBLOOD is a Go-based ransomware that quickly encrypts files while employing self-deletion tactics to obscure forensic traces, and it threatens data leaks through a TOR site, amplifying the potential impact on businesses. BQTLock operates stealthily, integrating into trusted Windows processes to delay visible harm, thus complicating early detection. It employs process injection techniques, a User Account Control (UAC) bypass, and autorun persistence to escalate privileges before launching further attacks like credential theft and screen capturing.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Moonrise
Indicators of Compromise (1 / 5 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 22d892ee990b3d75e3fff497b75667dd MD5 of ed5471d42bef6b32253e9c1aba49b01b8282fd096ad0957abcf1a1e27e8f7551 2026-03-08