Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
BQTLock is a ransomware-as-a-service operation that surfaced in mid-2025, ideologically aligned with pro-Iranian and pro-Palestinian interests and recruiting affiliates via Telegram to target Israeli, UAE and US organizations; it is associated with a tactical shift from the earlier 'Sicarii' operators.
BQTLock was publicly disclosed in July 2025 as a new ransomware strain and RaaS platform, with reporting attributing development to pro-Palestinian hacktivist personas (aliases such as 'Liwaa Mohammad' and 'Karim Fayad') and describing an ideological lean toward Iranian and Palestinian interests. Analysts linked the operation to a tactical shift by pro-Iranian ransomware operators previously associated with the 'Sicarii' brand.
The operation advertises free or low-cost RaaS access on Telegram and explicitly courts affiliates capable of striking Israeli entities, blending ideological targeting with a conventional affiliate revenue model. Vendor reporting has documented advanced detection-evasion techniques in BQTLOCK samples, and coverage continued into late 2025 and early 2026, indicating sustained activity.
Its documented targeting emphasizes the United Arab Emirates, Israel and the United States, with additional MENA-relevant claims. As with any RaaS leak-site or Telegram claim, individual victim assertions should be treated as unverified unless corroborated by a reputable source or the affected organization.
Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →
| Date | Victim | Country | Sector |
|---|---|---|---|
| 2025-10-11 | Adore UAE | UAE | Retail & E-Commerce |
| 2025-10-11 | EPS FUJ Private School UAE | UAE | Education |
| 2025-08-09 | European Business Server Cluster | — | Technology |
| 2025-07-31 | eFunda, Inc. | US | Technology |
| 2025-07-31 | USA Military Alumni Networks | US | Government & Defense |