Blue Locker
Threat Actor
Blue Locker ransomware demonstrates sophisticated technical capabilities, utilizing a combination of AES and RSA encryption algorithms while deliberately avoiding system-critical files to maintain persistence.
Blue Locker operates through a PowerShell-based loader that disables security defenses, escalates privileges, and appends “.blue” or “.bulock16” extensions to encrypted files.
The malware’s advanced evasion techniques include obfuscation of target strings, such as disguising “Chrome.exe” as Chinese characters to bypass detection systems.
Incidents Associated with this Threat
- August 6, 2025: Pakistan Petroleum Limited Foiled Ransomware Attempt
Malware Used by this Threat Actor
No malware identified for this threat actor.
