BLUE Locker ransomware was first observed in November 2021 but drew renewed attention after an attack on Pakistan Petroleum Limited (PPL) on 6 August 2025. The attackers encrypted servers and virtual machines, deleted backups and disrupted financial operations for two days. They claimed to have stolen about 1TB of data, although PPL denied that sensitive information had been compromised. Pakistan’s National CERT (NCERT) subsequently issued an emergency advisory to 39 government ministries and institutions.
These organisations were warned recipients, not confirmed victims; NCERT said its defences detected and blocked the malware at some other targeted organisations. PPL is the only publicly named confirmed victim.
Attribution remains unresolved. Resecurity and other researchers link Blue Locker to the Proton ransomware family, which the Israeli National Cyber Directorate and Fortinet have associated with probable Iranian origins. Independent researcher Andrey Zhdanov instead classifies matching `.blue` samples and `restore_file.txt` notes as MemeCryptor, an open-source ransomware project. The article says source-code transfers or reuse could explain the overlap, while unrelated malware also uses the `.blue` extension.
Blue Locker uses double extortion: data is reportedly stolen before encryption, while victims are threatened with publication. Reported access methods include phishing, insecure remote access, drive-by downloads and trojanised software. A PowerShell loader can disable defences and deliver the payload; the malware may bypass UAC, establish Registry Run-key persistence, terminate Chrome to target saved-password files, delete Volume Shadow Copies and stop services before encryption.
Reported cryptography varies between samples, with AES-RSA and ChaCha20-RSA both described. Organisations should review NCERT advisory NCA-38 and its listed indicators, particularly in Pakistan’s energy, government and technology sectors.