zerodayx1 is a pro-Palestinian hacktivist threat actor that has been publicly associated with the launch of the BQTLock Ransomware-as-a-Service operation. The group exemplifies the convergence of ideological hacktivism and financially motivated cyber extortion, pairing pro-Palestinian political messaging with a subscription-based ransomware business model. This positioning indicates an evolution from purely disruptive or propagandistic activity toward the operationalization of ransomware and extortion as part of a broader ideological campaign. High-confidence reporting links zerodayx1 to ransomware enablement and initial access-related criminal activity through its operation of a RaaS offering, but detailed victimology, tooling, and intrusion tradecraft beyond that association are not currently available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian actor operating BQTLock Ransomware-as-a-Service, merging ideological motives with extortion-driven business models.
zerodayx1 is a Lebanese pro-Palestinian hacktivist group that has pivoted to financially motivated ransomware operations with its BQTLock RaaS platform.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.