Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomwareUsed by 3 actorsExploits 1 CVE

Baqiyat 313 Locker

Baqiyat 313 Locker, also referred to as BQTlock, is a ransomware-as-a-service (RaaS) platform publicly disclosed in July 2025 and described as a separate platform used by pro-Palestinian and pro-Iranian regime-affiliated operators. Reporting cited in the content says Sicarii operators were redirected to BQTlock after Sicarii’s administrator said it could not handle a surge in affiliate requests. BQTlock is characterized as ideologically driven, emphasizing pro-Palestinian political messaging while conducting ransomware operations.

The malware uses double-extortion tactics. According to the content, BQTlock has primarily targeted organizations in the United Arab Emirates, the United States, and Israel since July 2025. Its leak site has published data from hospitality and education entities, including victims in the UAE, the US, and Israel. Related Telegram messaging advertised free RaaS access for hacktivists able to target the “Zionist entity,” and associated channels showed interest in critical infrastructure and military targets.

The content states BQTlock was purportedly developed by pro-Palestinian hacktivists Liwaa Mohammad and Karim Fayad, with Liwaa Mohammad operating under the broader Cyber Islamic Resistance umbrella. It also notes collaboration or association in related channels with the Cyber Fattah Team. On 20 December 2025, the Cyber Fattah Team reportedly claimed successful exploitation of React2Shell (CVE-2025-55182), a critical unauthenticated remote code execution vulnerability affecting React Server Components and the RSC Flight protocol, to deploy BQTlock against an Israeli-based victim. The victim was reportedly not listed on the BQTlock leak site, suggesting payment or a decision not to publish.

High-confidence aliases in the provided content are Baqiyat 313 Locker and BQTlock.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-55182React2ShellExploited in the wild

React2Shell: CVE-2025-55182, also known as "React2Shell," is a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC) and the RSC Flight protocol.

via halcyon attacks lookouthalcyon.ai
THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Liwaa Mohammad

"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."

via halcyon attacks lookouthalcyon.ai
Cyber Fattah Team

"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."

via halcyon attacks lookouthalcyon.ai
Cyber Islamic Resistance

"...move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also known as BQTlock ransomware..."

via halcyon attacks lookouthalcyon.ai
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.