BaqiyatLock
BaqiyatLock, also referred to as BQTlock, is a ransomware-as-a-service (RaaS) group. In the provided reporting, it is described as publicly offering free affiliate memberships or free affiliate access to hacktivists and other actors willing to target Israeli organizations or Israeli interests. The group is presented as introducing a financially motivated criminal vector alongside ideologically motivated pro-Iran hacktivist activity during the period following the February 28, 2026 U.S. and Israeli strikes on Iran. The reporting does not attribute BaqiyatLock to a state, but places it within the broader ecosystem of pro-Iran-aligned or opportunistically aligned activity observed on Telegram, X, and underground forums. The content specifically associates the group with ransomware operations through its RaaS model and with recruitment of affiliates for attacks against Israeli targets. Known alias: BQTlock.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pseudo-ransomware actor blending ideological and criminal motives, offering free affiliate access for attacks on Israeli organizations and deploying destructive pseudo-ransomware.
RaaS group offering free affiliate memberships to hacktivists willing to target Israel.
Ransomware-as-a-service group that publicly offered free affiliate access for operations targeting Israeli interests, suggesting opportunistic ideologically framed ransomware activity.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.