News Room
16
Share
highCyber Espionage

Middle East Ransomware Groups Exploit Cyber Espionage Tactics

Middle East-based ransomware groups are increasingly engaging in cyber espionage, targeting diplomatic entities and critical infrastructure to gather intelligence and exert geopolitical influence.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Middle East Ransomware Groups Exploit Cyber Espionage Tactics for ₿ 0.10 BTC. Contact us.

18 March 2026Last updated 18 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Ransomware Group
Geography:
Middle East
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

Middle East-based ransomware groups are increasingly engaging in cyber espionage, targeting diplomatic entities and critical infrastructure to gather intelligence and exert geopolitical influence. Notably, the BQT.Lock cyberattack group, led by Karim Fayad, exemplifies this trend by blending financial extortion with ideological motives linked to Hezbollah and Iranian state-linked cyber activities. (en.wikipedia.org)

Operational Overview

BQT.Lock, also known as BaqiyatLock, emerged in mid-2025 and operates as a ransomware-as-a-service (RaaS) platform, providing tools to other attackers. The group has rapidly expanded its operations, claiming hundreds of encryptions across the U.S., India, Saudi Arabia, UAE, and Israel. (en.wikipedia.org)

The group's leader, Karim Fayad, is identified as having links to Hezbollah’s Imam al-Mahdi Scouts and has previously been involved in pro-Palestinian hacking activities. This connection suggests that BQT.Lock's activities may serve both financial and ideological objectives, potentially supporting Hezbollah's operations. (en.wikipedia.org)

Technical Profile

BQT.Lock ransomware targets Windows systems, employing hybrid AES-256/RSA-4096 encryption and appending the extension ".bqtlock" to encrypted files. The malware utilizes process hollowing via File Explorer, creates backdoor accounts like "BQTLockAdmin," and disables defenses through API calls and boot manipulation. Before encrypting files, the attackers conduct network reconnaissance, moving through systems using tools like SMB and PsExec, and stealing data from browsers such as Chrome, Firefox, and Edge. (en.wikipedia.org)

Supply Chain Compromise and SIGINT-Linked Intrusions

BQT.Lock's operations have extended beyond direct attacks to include supply chain compromises. In late 2025, cybersecurity companies reported that BQT.Lock was using a RaaS model, offering different subscription levels and sharing profits with its partners. The group operates through TOR-based leak websites, Telegram bots, and dark web accounts, demanding ransom payments in Monero (XMR), typically between 13 and 40 XMR for each attack wave. (en.wikipedia.org)

Additionally, Iranian-backed hackers, identified as Mint Sandstorm (also known as Charming Kitten or APT35), have targeted high-ranking officials from U.S. presidential campaigns with spear-phishing attacks, using compromised email accounts to send malicious links. (en.wikipedia.org)

Diplomatic Targeting

In September 2025, an Iran-linked cyber group, identified by Israeli cybersecurity firm Dream as "Homeland Justice," launched a coordinated, multi-wave spear-phishing campaign targeting embassies, consulates, and international organizations worldwide. The campaign leveraged 104 compromised email accounts, including one belonging to the Omani Ministry of Foreign Affairs in Paris, to distribute phishing emails masquerading as legitimate diplomatic communications. The messages featured themes tied to geopolitical tensions and urged recipients to enable macros in Word documents, triggering malicious Visual Basic for Applications (VBA) payloads that allowed persistent access, system reconnaissance, and command-and-control (C2) communication. (linkedin.com)

Conclusion

The convergence of ransomware operations with cyber espionage tactics by Middle East-based groups like BQT.Lock and state-backed actors underscores a complex and evolving threat landscape. These actors are not only financially motivated but also strategically targeting diplomatic and critical infrastructure to gather intelligence and exert geopolitical influence. Organizations operating in the Middle East should enhance their cybersecurity measures, focusing on supply chain security, SIGINT-related vulnerabilities, and diplomatic communications to mitigate these sophisticated threats.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo