ZeroDayX1
ZeroDayX is a Lebanese-origin hacktivist–cybercriminal persona assessed as the primary operator and public face of the BQTLock (BaqiyatLock) ransomware ecosystem and the pro-Palestinian / Hezbollah-aligned collective commonly branded Liwaa Mohammad / Mohamed Brigade.
Initially active around 2023 with DDoS, defacement and data-leak operations, ZeroDayX pivoted in 2024–2025 to a structured Ransomware-as-a-Service (RaaS) platform (BQTLock), plus associated tools (BQTScanner, BQT OSINT), offering affiliates encryption, extortion and OSINT/recon capabilities under a Monero-based subscription model.
Open sources (Alma Research, Dos-Op, other CTI vendors) strongly link ZeroDayX1 to Karim Fayad, a Lebanese computer-engineering student alleged to be a Hezbollah cyber operative; some earlier reporting framed this as a dox by opponents that he publicly denied, but more recent OSINT (tattoos, overlapping accounts, biographical traces) now treats the link as highly probable.
ATT&CK