BQTLock, also referred to as baqiyat_313_locker, is a pro-Iranian and pro-Palestinian ransomware actor active since at least 2025. The group has been associated with politically motivated disruptive and extortion-oriented operations aligned with Iranian geopolitical interests rather than purely profit-driven cybercrime. Reported victimology includes organizations in the United Arab Emirates, the United States, and Israel. BQTLock is part of a broader ecosystem of pro-Iranian ransomware activity that has included other Iran-linked operators and campaigns. The actor is known for ransomware operations and is assessed to conduct attacks in support of ideological and influence-aligned objectives. High-confidence reporting ties the group to targeting patterns consistent with regional adversaries of Iran. Publicly available information in this context does not provide sufficient corroborated detail on specific intrusion chains, malware internals, or a fuller set of tactics and techniques beyond its use as a ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.