Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇶 IQ1 malware family

Liwaa Mohammad

Also known asliwaa_mohammad

Liwaa Mohammad is a pro-Palestinian, pro-Iran-aligned hacktivist group operating under the broader Cyber Islamic Resistance umbrella and within the wider Islamic Cyber Resistance / Cyber Isnaad Front ecosystem. Reporting places the group among Iraqi-linked cyber proxy and hacktivist networks that appear to coordinate from Iraqi territory as part of the Iraq-Iran cyber corridor. The group is explicitly identified alongside the 313 Team, Fatimion Cyber Team, FAD Team, AL Toufan, AL_Safwa313, Al Safwa, Unit 313, and Gaza313 in that ecosystem. Liwaa Mohammad is led by Karim Fayad, also known as ZeroDayX and ZeroDayX1. The group has been linked to the development and launch of the Baqiyat 313 Locker ransomware, also referred to as BQTlock and Baqiyatlock313. BQTlock is described as an ideologically driven Ransomware-as-a-Service platform used by pro-Palestinian and pro-Iranian regime-affiliated operators. It combines political messaging with double extortion and, since July 2025, has primarily targeted organizations in the UAE, the United States, and Israel. Reporting states that BQTlock has published stolen data from hospitality and education entities on its leak site. Liwaa Mohammad-related activity is tied to Telegram-based operations under the Cyber Islamic Resistance umbrella. Forwarded posts attributed to the group claimed leaks of an Israeli military database and a list of Israeli Mossad agents. Related communications also showed interest in targeting critical infrastructure and military entities. The Cyber Fattah Team is described as collaborating on Liwaa Mohammad Telegram channels, and reporting states Cyber Fattah Team claimed exploitation of React2Shell (CVE-2025-55182) to deploy BQTlock against an Israeli-based victim on 20 December 2025. Known aliases directly reflected in the content are Liwaa Mohammad and liwaa_mohammad.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • IQ
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.