BQTLock, also referred to as Baqiyat 313 Locker and BQTlock ransomware, is a ransomware-as-a-service operation publicly disclosed in July 2025. The reporting describes it as an ideologically driven, pro-Palestinian and pro-Iran-aligned ransomware operation that blends political messaging with double-extortion. It has primarily targeted organizations in the United Arab Emirates, the United States, and Israel since July 2025, and its leak site has published data from hospitality and education entities in those countries. BQTLock has also been listed among new ransomware variants tracked in July 2024, with claimed victims including USA Military Alumni Networks, eFunda, and Bizoneo. According to the cited reporting, BQTLock was purportedly developed by pro-Palestinian hacktivists Liwaa Mohammad and Karim Fayad. Liwaa Mohammad is described as operating under the broader Cyber Islamic Resistance umbrella, and Karim Fayad is identified as also using the aliases ZeroDayX and ZeroDayX1. BQTLock and Sicarii are described as separate RaaS platforms used by pro-Palestinian and pro-Iranian regime-affiliated operators. In March 2026, after Sicarii’s administrator said the group could not support a surge in affiliate requests, operators were redirected to BQTLock as the preferred ransomware platform for ideologically motivated attacks. BQTLock is advertised via Telegram, including offers of free RaaS access for hacktivists able to target the "Zionist entity." Related Cyber Islamic Resistance communications showed interest in targeting critical infrastructure and military entities, and forwarded Liwaa Mohammad claims involving an Israel military database and a list of Israeli Mossad agents. Reporting also links collaboration with the Cyber Fattah Team on Liwaa Mohammad channels. The Cyber Fattah Team claimed it used a functioning React2Shell exploit for initial access and, on 20 December 2025, reported successful exploitation of CVE-2025-55182 to deploy BQTLock against an Israeli-based victim.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian ideologically framed RaaS emphasizing political messaging; conducts double-extortion ransomware operations and runs a data leak site publishing victim data, with targeting noted in UAE, US, and Israel since July 2025.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in July 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.