Cyber Security News

New Blue Locker Ransomware Attacking Oil & Gas Sector in Pakistan

Pakistan’s National Cyber Emergency Response Team (NCERT) has issued urgent warnings to 39 government ministries following a sophisticated ransomware campaign targeting the country’s critical infrastructure.

The Blue Locker ransomware has successfully compromised Pakistan Petroleum Limited (PPL), the nation’s second-largest oil company, in an attack that occurred on August 6, 2025, just days before Pakistan’s Independence Day celebrations.

The ransomware campaign represents a significant escalation in cyber threats against South Asian critical infrastructure, with attackers successfully encrypting systems and exfiltrating over 1TB of sensitive data.

The breach affected crucial operational data, including Petrel Studio exploration files, production databases, operations plans, and financial records.

PPL’s spokesperson confirmed the incident, stating that the company immediately activated internal cybersecurity protocols and initiated a comprehensive forensic analysis to assess the full scope of the compromise.

Resecurity researchers noted that Blue Locker appears to be a variant of the Proton ransomware family, sharing similarities with previous strains including Limba, Zola, and Shinra.

The malware demonstrates sophisticated evasion capabilities and employs double extortion tactics, threatening to publish stolen data if ransom demands are not met.

Security analysts identified connections between this campaign and earlier ransomware operations, suggesting possible shared authorship or code reuse among cybercriminal groups.

The timing of the attack, coinciding with Pakistan’s national holiday, raises concerns about potential nation-state involvement rather than traditional cybercriminal motivations.

The strategic targeting of energy sector infrastructure suggests actors with geopolitical objectives, though attribution remains challenging due to deliberate obfuscation techniques employed by the attackers.

Advanced Persistence and Evasion Mechanisms

Blue Locker demonstrates remarkable sophistication in its persistence mechanisms, establishing multiple foothold techniques to maintain long-term access to compromised systems.

The ransomware achieves persistence by modifying the Windows registry, specifically inserting itself into the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\NT\CurrentVersion\Run key.

Ransom Note (Source – Resecurity)

This registry manipulation ensures automatic execution following system reboots, allowing the malware to maintain control even after restart attempts.

The malware employs advanced anti-analysis techniques, including process enumeration to identify and terminate security tools.

It specifically targets Chrome processes using XOR-encoded strings that appear as Chinese characters but decode to “Chrome.exe”.

Once located, Blue Locker forcibly terminates the browser process to bypass file locks and gain access to Chrome’s password database, subsequently encrypting these critical authentication files.

RSA and AES cryptographic provider (Source – Resecurity)

Blue Locker utilizes a combination of AES and RSA encryption algorithms, systematically encrypting files while deliberately avoiding system-critical directories such as Windows, System Volume Information, and Boot folders.

The ransomware appends the “.blue” extension to encrypted files and executes shadow copy deletion commands through wmic SHADOWCOPY DELETE, effectively preventing victims from utilizing built-in Windows recovery mechanisms to restore their data without paying the demanded ransom.

Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…

1 hour ago

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

2 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

3 hours ago

FBI Cuts Accenture Contractor Over Unpatched PeopleSoft Flaw Exposing Thousands

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

3 hours ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

4 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

4 hours ago