News Room
16
Share
mediumCyber Espionage

Emerging Ransomware Groups Targeting East Asia Amid Geopolitical Tensions

New ransomware groups, including BQT.Lock and CyberVolk, are increasingly targeting East Asian entities, leveraging geopolitical conflicts to enhance their operations.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Emerging Ransomware Groups Targeting East Asia Amid Geopolitical Tensions for ₿ 0.10 BTC. Contact us.

21 March 2026Last updated 21 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
Ransomware Group
Geography:
East Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Overview

In early 2026, the cyber threat landscape in East Asia has been marked by the emergence of new ransomware groups, notably BQT.Lock and CyberVolk. These groups are capitalizing on regional geopolitical tensions to expand their operations, posing significant risks to both corporate and governmental entities.

BQT.Lock Cyberattack Group

BQT.Lock, also known as BaqiyatLock, surfaced in mid-2025 and operates under the leadership of Karim Fayad. This group employs a Ransomware-as-a-Service (RaaS) model, providing ransomware tools to other attackers. Their activities blend financial extortion with ideological motives linked to Hezbollah and Iranian state-sponsored cyber operations. In late 2025, BQT.Lock's operations expanded to include targets in East Asia, with notable attacks on Japanese companies such as Anabuki Housing Service Co., Ltd. (en.wikipedia.org)

CyberVolk

CyberVolk, a pro-Russian hacktivist collective and RaaS operator, emerged in May 2024. Despite its pro-Russian alignment, the group has been linked to operations targeting East Asian entities. CyberVolk has claimed responsibility for over 120 attacks against government ministries, defense contractors, scientific institutes, and critical infrastructure operators across various regions, including East Asia. (en.wikipedia.org)

Operational Tactics and Tools

Both BQT.Lock and CyberVolk utilize sophisticated tactics to infiltrate and compromise their targets. These include spear-phishing campaigns, exploitation of known vulnerabilities, and the deployment of custom malware. For instance, BQT.Lock has been reported to use legitimate remote administration and management tools to maintain persistence within compromised networks. (fortiguard.fortinet.com)

Impact and Implications

The activities of BQT.Lock and CyberVolk have significant implications for East Asian organizations. Their operations not only result in financial losses due to ransom demands but also pose risks to sensitive data and critical infrastructure. The geopolitical affiliations of these groups suggest that their attacks may be part of broader state-sponsored cyber strategies, potentially leading to increased cyber tensions in the region.

Recommendations

Organizations in East Asia should enhance their cybersecurity posture by implementing comprehensive security measures, including regular system updates, employee training on phishing threats, and robust incident response plans. Collaboration with international cybersecurity agencies and sharing threat intelligence can also aid in mitigating the risks posed by these emerging ransomware groups.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo