Skip to content
Emerging Ransomware: BQTLock and GREENBLOOD

Emerging Ransomware: BQTLock and GREENBLOOD

Reddit /u/malwaredetector February 11, 2026

Full article: TL;DR BQTLock is a stealthy ransomware-linked chain. It injects Remcos into explorer.exe, performs UAC bypass via fodhelper.exe, and sets autorun persistence to keep elevated access after reboot, then shifts into credential theft / screen capture, turning the incident into both ransomware + data breach risk. GREENBLOOD is a Go-based ransomware built for rapid impact: ChaCha8-based encryption can disrupt operations in minutes, followed by self-deletion / cleanup attempts to reduce forensic visibility, plus TOR leak-site pressure to add extortion leverage beyond recovery. In both cases, the critical window is pre-encryption / early execution : stealth setup (BQTLock) and fast encryption (GREENBLOOD) compress response time and raise cost fast. submitted by /u/malwaredetector [link] [ ]