News Room
16
Share
mediumOffensive Tools

Emerging Cyber Threats in the Middle East: Advanced Malware Analysis

Recent cyber activities in the Middle East reveal the rise of sophisticated malware families, including polymorphic ransomware, rootkits, and fileless malware, posing medium-level threats from cybercriminal actors.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Emerging Cyber Threats in the Middle East: Advanced Malware Analysis for ₿ 0.10 BTC. Contact us.

23 March 2026Last updated 23 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Medium
Actor Type:
Cybercriminal
Geography:
Middle East
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

The Middle East has witnessed a surge in cybercriminal activities, with new and sophisticated malware families emerging. This briefing provides an analysis of these developments, focusing on novel malware strains, reverse engineering findings, and command-and-control (C2) infrastructure analysis.

Emergence of New Malware Families

BQT.Lock Ransomware

In mid-2025, the BQT.Lock ransomware group, also known as BaqiyatLock, emerged from the Middle East. Led by Karim Fayad, this group operates a Ransomware-as-a-Service (RaaS) platform, blending financial extortion with ideological motives linked to Hezbollah and Iranian state activities. BQT.Lock targets Windows systems, employing hybrid AES-256/RSA-4096 encryption and appending the .bqtlock extension to encrypted files. The malware utilizes process hollowing via File Explorer, creates backdoor accounts like "BQTLockAdmin," and disables defenses through API calls and boot manipulation. Before encryption, it conducts network reconnaissance, moves laterally using tools like SMB and PsExec, and steals data from browsers such as Chrome, Firefox, and Edge. The malware also creates log files, such as bqt_log.txt, to record actions taken during the attack. (en.wikipedia.org)

Vect Ransomware Group

The Vect ransomware group has rapidly matured, targeting high-value infrastructure in Brazil and South Africa with custom C++ malware. Distinguishing itself with the high-speed ChaCha20-Poly1305 algorithm and intermittent encryption, Vect can paralyze Windows, Linux, and VMware ESXi systems with remarkable efficiency. (cyware.com)

Reverse Engineering Findings

Reverse engineering of BQT.Lock reveals its sophisticated evasion techniques, including process hollowing and the creation of backdoor accounts. The malware's ability to disable security defenses through API calls and boot manipulation indicates a high level of technical proficiency. Its network reconnaissance capabilities and lateral movement using SMB and PsExec suggest a well-coordinated attack strategy. The theft of browser data and the creation of log files for post-attack analysis highlight the group's focus on comprehensive data exfiltration and operational transparency.

Polymorphic Ransomware and Rootkits

The Vect ransomware's use of the ChaCha20-Poly1305 algorithm and intermittent encryption techniques exemplify the trend towards polymorphic ransomware, which adapts its code to evade detection. Additionally, the creation of backdoor accounts and the use of process hollowing techniques are indicative of rootkit functionalities, allowing the malware to maintain persistent access and control over infected systems.

Fileless Malware and C2 Infrastructure Analysis

While specific details on fileless malware and C2 infrastructure used by these groups are limited, the observed behaviors suggest the use of sophisticated C2 mechanisms. The malware's ability to disable security defenses and maintain persistence indicates the use of advanced C2 infrastructure, potentially involving encrypted communication channels and decentralized command structures to evade detection and takedown efforts.

Conclusion

The Middle East's cyber threat landscape is evolving, with cybercriminal groups like BQT.Lock and Vect deploying advanced malware families that incorporate polymorphic ransomware, rootkits, and fileless techniques. Their sophisticated C2 infrastructures and operational strategies pose medium-level threats to regional organizations. Continuous monitoring, advanced detection mechanisms, and proactive defense strategies are essential to mitigate these emerging cyber threats.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo