◇ SIGN IN
← all actors
ransomware

BQTLock

activemedium confidence
Ransomware
BQTLOCKBQT.Lock
Attribution
RaaS (pro-Iran / pro-Palestinian aligned)
Origin
Unknown
First seen
2025
Last active
2026
Motivation
Hacktivism / ransomware (ideologically aligned, financially motivated)
Confidence
medium
MENA targeting
UAE, Israel, Saudi Arabia
Sectors
Cross-sector; pro-Palestinian hacktivist-branded RaaS

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE, Israel, Saudi Arabia (Cross-sector; pro-Palestinian hacktivist-branded RaaS sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

BQTLock is a ransomware-as-a-service operation that surfaced in mid-2025, ideologically aligned with pro-Iranian and pro-Palestinian interests and recruiting affiliates via Telegram to target Israeli, UAE and US organizations; it is associated with a tactical shift from the earlier 'Sicarii' operators.

History

BQTLock was publicly disclosed in July 2025 as a new ransomware strain and RaaS platform, with reporting attributing development to pro-Palestinian hacktivist personas (aliases such as 'Liwaa Mohammad' and 'Karim Fayad') and describing an ideological lean toward Iranian and Palestinian interests. Analysts linked the operation to a tactical shift by pro-Iranian ransomware operators previously associated with the 'Sicarii' brand.

The operation advertises free or low-cost RaaS access on Telegram and explicitly courts affiliates capable of striking Israeli entities, blending ideological targeting with a conventional affiliate revenue model. Vendor reporting has documented advanced detection-evasion techniques in BQTLOCK samples, and coverage continued into late 2025 and early 2026, indicating sustained activity.

Its documented targeting emphasizes the United Arab Emirates, Israel and the United States, with additional MENA-relevant claims. As with any RaaS leak-site or Telegram claim, individual victim assertions should be treated as unverified unless corroborated by a reputable source or the affected organization.

Notable campaigns

2025
BQTLock RaaS launch
Emerged July 2025 recruiting affiliates via Telegram to attack Israeli, UAE and US targets (claimed).
2025
Sicarii-to-BQTLock shift
Analysts assessed pro-Iranian 'Sicarii' operators pivoted to the BQTLock brand (claimed/analytic).

Claimed victims · 5 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Adore UAEUAERetail & E-Commerce
EPS FUJ Private School UAEUAEEducation
European Business Server ClusterTechnology
eFunda, Inc.USTechnology
USA Military Alumni NetworksUSGovernment & Defense