Mercenary Spyware and Ransomware Threats in Central Asia: A Rising Concern
Central Asia faces escalating cyber threats from ransomware groups leveraging mercenary spyware and commercial offensive tools, posing significant risks to regional security.
Encrygma is selling the entire Full Cyber Weapon Research of Mercenary Spyware and Ransomware Threats in Central Asia: A Rising Concern for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- Central Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of April 2026, Central Asia is witnessing a surge in cyber threats, particularly from ransomware groups employing mercenary spyware and commercial offensive tools. These actors are increasingly targeting critical infrastructure and sensitive data, posing significant risks to regional security and economic stability.
Emergence of Ransomware Groups in Central Asia
In mid-2025, the BQT.Lock cyberattack group, also known as BaqiyatLock, gained prominence. Operating from the Middle East and led by Karim Fayad, BQT.Lock combines financial extortion with ideological motives linked to Hezbollah and Iranian state-sponsored cyber activities. The group utilizes a ransomware-as-a-service (RaaS) model, offering various subscription levels and sharing profits with partners. Their operations have targeted entities in the U.S., India, Saudi Arabia, UAE, and Israel, employing sophisticated techniques such as data exfiltration via Discord webhooks and credential theft from browsers. (en.wikipedia.org)
Integration of Commercial Spyware and Offensive Tools
The convergence of cyber espionage and cybercrime is evident in the activities of state-aligned Advanced Persistent Threat (APT) groups. These actors are increasingly deploying ransomware, blurring the lines between traditional espionage and financial cybercrime. This trend underscores the evolving nature of cyber threats, where state-sponsored entities leverage cybercriminal tactics and malware to achieve their objectives. (eset.com)
Surveillance-as-a-Service and Exploit Brokers
The proliferation of surveillance-as-a-service platforms and exploit brokers has facilitated the availability of sophisticated cyberattack tools. Companies like Cytrox, established in 2017, develop malware used for cyberattacks and covert surveillance. Their Predator spyware has been employed to target high-profile individuals, including politicians and journalists, highlighting the dual-use nature of such technologies. In 2023, the U.S. Department of Commerce added Cytrox to its Entity List, and in March 2024, the U.S. Department of Treasury imposed sanctions on Cytrox AD of North Macedonia and the Intellexa Consortium, its parent firm, for trafficking in cyber exploits. (en.wikipedia.org)
Implications for Central Asia
The integration of mercenary spyware and commercial offensive tools by ransomware groups poses significant challenges for Central Asia. The region's critical infrastructure and sensitive data are increasingly at risk, necessitating enhanced cybersecurity measures and international cooperation. The blurred lines between state-sponsored and cybercriminal activities further complicate the threat landscape, requiring a nuanced and comprehensive response.
Conclusion
The evolving cyber threat landscape in Central Asia, characterized by ransomware groups leveraging mercenary spyware and commercial offensive tools, demands immediate and sustained attention. Stakeholders must collaborate to develop robust defense strategies, enhance digital literacy, and establish frameworks to counteract the multifaceted nature of these cyber threats.
Highlights:
- As Cybercrime Soars in Central Asia, Digital Literacy Lags Behind – The Diplomat, Published on Wednesday, March 25
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

AI-Powered Cyber Attacks Accelerate: Microsoft Report Highlights Autonomous Speed

Global Surge in Mercenary Spyware: Apple Issues High-Confidence Alerts Across 110 Nations

