QWCrypt Locker Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 9, 2025
Last Seen
December 9, 2025

QWCrypt Locker is a ransomware family that, according to the articles, is being used by the GOLD BLADE group via a custom version.

Overview

QWCrypt Locker is a ransomware family that, according to the articles, is being used by the GOLD BLADE group via a custom version. This tool enables data exfiltration in addition to ransomware deployment, indicating a dual-extortion capability and evolving threat tactics in the ransomware landscape.

Related Threat Clusters

  • GOLD BLADE Ransomware Campaign Using QWCrypt Locker Identified

    Between February 2024 and August 2025, Sophos threat analysts identified nearly 40 intrusions linked to the GOLD BLADE ransomware campaign. This campaign utilizes a custom QWCrypt locker for data exfiltration and…

    3 articles · Updated December 9, 2025

Recent Intelligence Reports

  • GOLD BLADE Using Custom QWCrypt Locker that Allows Data Exfiltration and Ransomware Deployment — Cybersecuritynews · December 9, 2025
  • GOLD BLADE Exploiting Custom QWCrypt Locker for Data Exfiltration and Ransomware Deployment — Cyberpress · December 9, 2025
  • GOLD BLADE: Custom QWCrypt Locker for Data Exfiltration and Ransomware Deployment — Gbhackers · December 9, 2025

Related Entities

CVSS v3.1 Breakdown