Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CTU researchers have also identified the BaqiyatLock (also known as BQTlock) ransomware-as-a-service (RaaS) group offering free affiliate memberships to any hacktivists who can "target the Zionist entity"... Organizations should also review their business continuity plans and restoration processes to address ransomware or wiper malware attacks.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation offering affiliate access to hacktivists targeting Israeli interests.
A ransomware-as-a-service operation offering affiliate access for attacks framed around targeting Israeli interests.
Ransomware that encrypts victim files using AES+RSA, appends the .BQTLOCK extension, drops ransom notes named READ_ME_NOW_<numbers>.txt, changes the desktop wallpaper, and instructs victims to contact the operators via Telegram or Twitter for payment and decryption. The content also indicates it is positioned as a RaaS offering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.