GOLD BLADE Ransomware Campaign Using QWCrypt Locker Identified
First seen 9 Dec 2025, 16:53 UTC
•

•95% similarity
•61
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Between February 2024 and August 2025, Sophos threat analysts identified nearly 40 intrusions linked to the GOLD BLADE ransomware campaign. This campaign utilizes a custom QWCrypt locker for data exfiltration and ransomware deployment, affecting various organizations during this period.
ThreatCluster AI
How this analysis works