Threat Actor Characterization
BQT OSINT
ID: e7989a1b480a1ac465a3e99715c18df365519| BQTosint | — | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
BQT OSINT (also exposed as BQT Bot OSINT via Telegram bot @BQTosintBot) is a paid OSINT and data-enrichment service operated by the Zerodayx1 / Liwaa Muhammad cluster behind BQTLock ransomware, BQTscanner and associated RaaS offerings. The service uses a point-based model purchased in Monero (XMR) and redeemed through vouchers sent by ZeroDayX1. It is promoted inside the BQTLock RaaS ecosystem and by allied channels (e.g., Cyber Fattah team) as an OSINT backend for members, suggesting that it provides domain- and organisation-centric intelligence to support targeting, extortion and reconnaissance. External reporting also describes BQT Bot OSINT as a recruitment and influence instrument that leverages emotional-intelligence tactics to attract and retain affiliates within the Zerodayx1 group. Ref: WatchGuard BQTLock tracker; Alma Research special report on BQTLock and Karim Fayad; Orange Cyberdefense Zerodayx1 Group profile; Telemetr mirrors of BQTLock RaaS and Cyber Fattah posts.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1591 | Gather Victim Org Information | TA0043 |
|
| T1590.001 | Domain Properties | TA0043 |
|
| T1593 | Search Open Websites/Domains | TA0043 |
|
| T1596 | Search Open Technical Databases | TA0043 |
|
BQT OSINT / BQT Bot OSINT
Classification: TLP:WHITE – Tooling profile
Author: iQBlack Team
Executive Summary
BQT OSINT (also branded as BQT Bot OSINT, accessed via Telegram bot @BQTosintBot) is a paid OSINT / data-enrichment service operated by the same ecosystem behind BaqiyatLock/BQTLock and the tools BQTScanner and BQTLock RaaS, led by ZeroDayX1 / Liwaa Muhammad.
The service is exposed as a point-based search system: users buy “points” with Monero (XMR), receive a voucher via ZeroDayX1, and redeem it inside the bot to perform lookups. Promotional posts from Cyber Fattah team and the BQTLock RaaS channel frame it as part of the broader Baqiyat toolset and even bundle “unlimited search points on the BQT OSINT tool” with BQTLock subscription offers.
External research on the Zerodayx1 Group describes BQT Bot OSINT not only as a technical data-access tool, but also as a recruitment and influence instrument that leverages “emotional intelligence” to draw sympathisers into the RaaS ecosystem and cultivate loyalty.