← Back to feed
Breaches & RansomwareEmerging1 sourceSep 25, 2026 · 13:46via Malware.news

Dark Web Profile: Blue Locker Ransomware

Brief

Threat Actor Profile: Blue Locker Ransomware

Blue Locker Ransomware, first detected in late 2021, the group stayed low-profile for years before making global headlines in August 2025 with a targeted attack on Pakistan Petroleum Limited (PPL), the country’s second-largest oil and gas producer.

The attack encrypted servers, wiped backups, and brought financial operations to a standstill for two days, prompting Pakistan’s National CERT to issue an emergency advisory to 39 government ministries and institutions.

However, attribution remains vague due to competing analyses linking the malware to the Iranian-associated Proton ransomware family on one hand and to an open-source project called MemeCryptor on the other.

Threat Actor card for Blue Locker

Who is Blue Locker?

Read more on Malware.news→