Liwaa Mohammad is a pro-Palestinian, pro-Iran-aligned hacktivist group operating within the broader Cyber Islamic Resistance umbrella and associated with the Islamic Cyber Resistance / Cyber Isnaad Front ecosystem. Reporting places the group within an Iraq-linked cluster of militia-aligned cyber actors that includes the 313 Team, Fatimion Cyber Team, FAD Team, AL Toufan, AL_Safwa313, Al Safwa, Unit 313, and Gaza313, with apparent coordination from Iraqi territory. The group has been linked to Karim Fayad, also known as ZeroDayX and ZeroDayX1. Liwaa Mohammad has been associated with leak and doxxing activity, including distribution of purported intelligence and military-related datasets, although the authenticity of some claimed leaks has not been verified and therefore should be treated cautiously. The group is also tied to ransomware activity through Baqiyat 313 Locker, also known as BQTlock or Baqiyatlock313, an ideologically framed ransomware operation blending political messaging with double-extortion. BQTlock has been described as a Ransomware-as-a-Service offering promoted to hacktivists aligned against Israeli targets, and Liwaa Mohammad has been identified as one of the actors behind its development and promotion. Operationally, the group fits the broader conflict-driven Middle Eastern hacktivist model centered on propaganda, retaliation narratives, data theft, public leaks, and coercive disruption. Its observed behavior supports capabilities in initial access, exfiltration, extortion, reconnaissance, and DDoS-aligned coalition activity through its ecosystem relationships. Liwaa Mohammad’s activity is best understood as part of a deniable proxy-style cyber environment in which ideologically motivated hacktivist branding overlaps with militia-linked and pro-Iranian influence structures.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist leak-and-doxxing channel distributing purported Israeli intelligence and military-related datasets.
Pro-Palestinian hacktivist group (under Cyber Islamic Resistance) associated in the reporting with development/promotion of BQTLock and with leaking claimed Israeli military/Mossad-related data via Telegram.
Iraqi territory-based pro-Iran cyber proxy group within the Islamic Cyber Resistance ecosystem.
Liwaa Mohammad is a pro-Palestine hacktivist group that has developed and deployed its own ransomware strain, Baqiyatlock313.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.