Pay2Key is an Iran-linked ransomware operation first observed in 2020 and widely associated with activity aligned to Iranian state interests. It has been linked by multiple researchers to Fox Kitten and described as a ransomware-as-a-service operation that has targeted Israeli organizations, later expanding to additional victims including a U.S. healthcare organization. Reported targeting has included industrial, insurance, logistics, healthcare, and broader enterprise environments, with some campaigns framed as disruptive or punitive rather than purely financially motivated.
Pay2Key has been used to encrypt servers and workstations and, in some campaigns, to steal and leak victim data for extortion pressure. Early operations against Israeli entities were associated with exploitation of exposed internet-facing systems, including VPN and remote access infrastructure, as well as RDP abuse and brute forcing. Later reporting also tied Pay2Key delivery to phishing-led intrusion chains in attacks against Russian organizations, where it appeared as a final payload delivered through loaders and droppers. Operators have also used legitimate remote access software and credential theft tooling to move through victim environments before ransomware deployment.
The malware and its surrounding tradecraft emphasize operational speed, anti-forensics, and defense evasion. Reported behaviors include identifying host IP and MAC addresses, deleting logs, self-deletion, clearing evidence after execution, disabling or impairing defensive controls, and using encrypted communications. In Windows intrusions, operators have been observed harvesting credentials, enumerating hosts and backup systems, and deploying the ransomware through self-extracting archives. Analysis of a 2026 build indicates the Windows encryptor is based on Mimic, itself derived from leaked Conti code, and uses ChaCha20 for file encryption with asymmetric protection of per-file keys. The ransomware can terminate services and processes to unlock files and accelerate impact.
Pay2Key has also evolved beyond Windows. A Linux variant has been observed targeting organizational servers, virtualization hosts, and cloud workloads. That variant requires elevated privileges, disables security frameworks, kills services and processes, enumerates mounted filesystems, persists across reboot, and encrypts data using ChaCha20. Its design indicates a focus on infrastructure-layer disruption while preserving enough system functionality to present a ransom demand.
Across reporting, Pay2Key stands out as part of the broader convergence between state-linked Iranian cyber operations and criminal ransomware tradecraft. It has been described as a vehicle for extortion, disruption, and plausible deniability, with some campaigns showing characteristics consistent with geopolitical retaliation or coercive signaling rather than conventional profit-maximizing ransomware behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The analysis of the infrastructure of Habana identified a vulnerable Fortinet server that was breached and its credentials were leaked to an underground forum. This server was vulnerable to Fortinet SSL VPN (CVE-2018-13379). We assess that this server was hacked by the threat actor using this exploit. | We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
When deploying the Pay2Key ransomware, the attackers employ heavy anti-forensic techniques to cover their tracks.
Early May 2021 saw another set of disruptive ransomware attacks attributed to Iran targeting Israel from the n3tw0rm ransomware group, a newly-identified threat actor with links to the 2020 Pay2Key attacks.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Halcyon and Beazley Security published a joint report detailing the attack chain: compromised admin credentials, a week of dormancy, TeamViewer for access...
Security researchers have uncovered a series of highly sophisticated Fluffy Wolf phishing attacks targeting Russian organizations across various critical sectors.
To remain hidden, the threat actors inject these payloads into trusted Windows processes such as RegAsm.exe, InstallUtil.exe, and MSBuild.exe.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Once PowerLoader infiltrates a target host, it spawns hidden PowerShell instances to retrieve additional malicious scripts directly from the command-and-control (C2) server. These scripts systematically deploy the final payloads...
Halcyon and Beazley Security published a joint report detailing the attack chain: compromised admin credentials, a week of dormancy, TeamViewer for access...
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2"). | Examples include: "encrypts some C2 with RSA", "RSA encryption for C2 communications", "hard-coded RSA public key", "RSA-2048", "RSA-4096", and "REvil has encrypted C2 communications with the ECIES algorithm".
Today, the Pay2Key ransomware operation leaked data allegedly stolen from Habana Labs during a cyberattack.
The encryptor terminates 60+ services and 40+ processes before encryption, including: Services: AcronisAgent, BackupExecJobEngine, CAARCUpdateSvc... | The encryptor terminates 60+ services and 40+ processes before encryption, including... Processes: sqlservr, sqlagent, msaccess, mysqld, oracle, python, node, java, Raccine, Sysmon...
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tags: ... pay2key ... ransomware ... SamSam ...
Ransomware used by Fluffy Wolf for financial extortion; it uses anti-forensic behavior including overwriting its own executable with zeros via fsutil before deleting it.
Шифровальщик, развернутый в системе жертвы; шифрует файлы, добавляя расширение .ywgulm_p2k, и оставляет записку с требованием выкупа на русском, английском и испанском языках.
Iran-linked ransomware used against a U.S. healthcare organization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.