Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Attribution ≠ confirmation. BQTLock is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
See the analysis →The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for BQTLock — see the competing-hypotheses breakdown for how confident this attribution really is.
See the analysis →