Emerging Ransomware Groups Targeting East Asia Amid Geopolitical Tensions
New ransomware groups, including BQT.Lock and CyberVolk, are increasingly targeting East Asian entities, leveraging geopolitical conflicts to enhance their operations.
Encrygma is selling the entire Full Cyber Weapon Research of Emerging Ransomware Groups Targeting East Asia Amid Geopolitical Tensions for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- Ransomware Group
- Geography:
- East Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Overview
In early 2026, the cyber threat landscape in East Asia has been marked by the emergence of new ransomware groups, notably BQT.Lock and CyberVolk. These groups are capitalizing on regional geopolitical tensions to expand their operations, posing significant risks to both corporate and governmental entities.
BQT.Lock Cyberattack Group
BQT.Lock, also known as BaqiyatLock, surfaced in mid-2025 and operates under the leadership of Karim Fayad. This group employs a Ransomware-as-a-Service (RaaS) model, providing ransomware tools to other attackers. Their activities blend financial extortion with ideological motives linked to Hezbollah and Iranian state-sponsored cyber operations. In late 2025, BQT.Lock's operations expanded to include targets in East Asia, with notable attacks on Japanese companies such as Anabuki Housing Service Co., Ltd. (en.wikipedia.org)
CyberVolk
CyberVolk, a pro-Russian hacktivist collective and RaaS operator, emerged in May 2024. Despite its pro-Russian alignment, the group has been linked to operations targeting East Asian entities. CyberVolk has claimed responsibility for over 120 attacks against government ministries, defense contractors, scientific institutes, and critical infrastructure operators across various regions, including East Asia. (en.wikipedia.org)
Operational Tactics and Tools
Both BQT.Lock and CyberVolk utilize sophisticated tactics to infiltrate and compromise their targets. These include spear-phishing campaigns, exploitation of known vulnerabilities, and the deployment of custom malware. For instance, BQT.Lock has been reported to use legitimate remote administration and management tools to maintain persistence within compromised networks. (fortiguard.fortinet.com)
Impact and Implications
The activities of BQT.Lock and CyberVolk have significant implications for East Asian organizations. Their operations not only result in financial losses due to ransom demands but also pose risks to sensitive data and critical infrastructure. The geopolitical affiliations of these groups suggest that their attacks may be part of broader state-sponsored cyber strategies, potentially leading to increased cyber tensions in the region.
Recommendations
Organizations in East Asia should enhance their cybersecurity posture by implementing comprehensive security measures, including regular system updates, employee training on phishing threats, and robust incident response plans. Collaboration with international cybersecurity agencies and sharing threat intelligence can also aid in mitigating the risks posed by these emerging ransomware groups.
Highlights:
- U.S. braces for cyberspace retaliation from Iran, Published on Tuesday, March 03
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



