Baqiyat 313 Locker
Baqiyat 313 Locker, also referred to as BQTlock, is a ransomware-as-a-service (RaaS) platform publicly disclosed in July 2025 and described as a separate platform used by pro-Palestinian and pro-Iranian regime-affiliated operators. Reporting cited in the content says Sicarii operators were redirected to BQTlock after Sicarii’s administrator said it could not handle a surge in affiliate requests. BQTlock is characterized as ideologically driven, emphasizing pro-Palestinian political messaging while conducting ransomware operations.
The malware uses double-extortion tactics. According to the content, BQTlock has primarily targeted organizations in the United Arab Emirates, the United States, and Israel since July 2025. Its leak site has published data from hospitality and education entities, including victims in the UAE, the US, and Israel. Related Telegram messaging advertised free RaaS access for hacktivists able to target the “Zionist entity,” and associated channels showed interest in critical infrastructure and military targets.
The content states BQTlock was purportedly developed by pro-Palestinian hacktivists Liwaa Mohammad and Karim Fayad, with Liwaa Mohammad operating under the broader Cyber Islamic Resistance umbrella. It also notes collaboration or association in related channels with the Cyber Fattah Team. On 20 December 2025, the Cyber Fattah Team reportedly claimed successful exploitation of React2Shell (CVE-2025-55182), a critical unauthenticated remote code execution vulnerability affecting React Server Components and the RSC Flight protocol, to deploy BQTlock against an Israeli-based victim. The victim was reportedly not listed on the BQTlock leak site, suggesting payment or a decision not to publish.
High-confidence aliases in the provided content are Baqiyat 313 Locker and BQTlock.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
React2Shell: CVE-2025-55182, also known as "React2Shell," is a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC) and the RSC Flight protocol.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."
"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."
"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian ransomware used by pro-Iranian operators, targeting organizations in the U.A.E., the U.S., and Israel.
Ransomware-as-a-Service platform used by pro-Palestinian/pro-Iranian-aligned operators; uses double-extortion (encryption plus data theft/leak) and emphasizes political messaging. Reported deployments include exploitation of React2Shell (CVE-2025-55182) for initial access.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.