Actor de amenaza individual

ZeroDayX1

ZeroDayX is a Lebanese-origin hacktivist–cybercriminal persona assessed as the primary operator and public face of the BQTLock (BaqiyatLock) ransomware ecosystem and the pro-Palestinian / Hezbollah-aligned collective commonly branded Liwaa Mohammad / Mohamed Brigade.

Initially active around 2023 with DDoS, defacement and data-leak operations, ZeroDayX pivoted in 2024–2025 to a structured Ransomware-as-a-Service (RaaS) platform (BQTLock), plus associated tools (BQTScanner, BQT OSINT), offering affiliates encryption, extortion and OSINT/recon capabilities under a Monero-based subscription model.

Open sources (Alma Research, Dos-Op, other CTI vendors) strongly link ZeroDayX1 to Karim Fayad, a Lebanese computer-engineering student alleged to be a Hezbollah cyber operative; some earlier reporting framed this as a dox by opponents that he publicly denied, but more recent OSINT (tattoos, overlapping accounts, biographical traces) now treats the link as highly probable.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19

ATT&CK

MITRE ATT&CK

T1041Exfiltration Over C2 Channel
T1053.005Scheduled Task
T1055.012Process Hollowing
T1071.001Web Protocols
T1078Valid Accounts
T1190Exploit Public-Facing Application
T1486Data Encrypted for Impact
T1490Inhibit System Recovery
T1497.001System Checks
T1555.003Credentials from Web Browsers
T1566.001Spearphishing Attachment
T1583.006Web Services
T1587.001Malware
T1588.002Tool
T1590Gather Victim Network Information