Pay2Key is a Windows ransomware family and associated extortion operation active since 2020. Its original C++ encryptor uses AES and RSA to encrypt victim data and demand payment for decryption. It communicates with command-and-control infrastructure over TCP, transmits its public key, and uses RSA-encrypted communications. It can identify the compromised host’s IP and MAC addresses and delete its own logs to hinder investigation.
Pay2Key operations have combined encryption of servers and workstations with data theft and publication of stolen information to pressure victims. Early campaigns primarily targeted Israeli organizations across industrial, insurance, logistics, and technology sectors, with additional activity in Europe. The operation has historical links to Iranian actors, including Fox Kitten. Intrusions have involved exploitation of exposed enterprise applications and VPN appliances, RDP exploitation and brute forcing, and supply-chain access through previously compromised companies. Operators have used reverse-proxy tools for network access and created local administrator accounts for persistence.
Later activity includes an attack against a U.S. healthcare provider in 2026 and deployment by Fluffy Wolf against Russian organizations. Fluffy Wolf delivered a Mimic-based payload bearing the Pay2Key name through phishing emails containing malicious archives or links to externally hosted archives, using PowerLoader and PureCrypter in the delivery chain. Observed anti-forensic behavior includes overwriting the ransomware executable with zeros before deleting it. The historical Iran-linked operation and later use of the Pay2Key name by other actors should not be treated as evidence of common operational control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The analysis of the infrastructure of Habana identified a vulnerable Fortinet server that was breached and its credentials were leaked to an underground forum. This server was vulnerable to Fortinet SSL VPN (CVE-2018-13379). We assess that this server was hacked by the threat actor using this exploit. | We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
We estimate with medium to high confidence that Pay2Key is a new operation conducted by Fox Kitten... The Pay2Key‘s modus operandi was to execute a ransomware attack... encrypts servers and workstations, steals and leaks information.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When deploying the Pay2Key ransomware, the attackers employ heavy anti-forensic techniques to cover their tracks.
Early May 2021 saw another set of disruptive ransomware attacks attributed to Iran targeting Israel from the n3tw0rm ransomware group, a newly-identified threat actor with links to the 2020 Pay2Key attacks.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers have uncovered a series of highly sophisticated Fluffy Wolf phishing attacks targeting Russian organizations across various critical sectors.
The lineage is visible in the service and process kill lists. The encryptor terminates 60+ services and 40+ processes before encryption...
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
Once PowerLoader infiltrates a target host, it spawns hidden PowerShell instances to retrieve additional malicious scripts directly from the command-and-control (C2) server. These scripts systematically deploy the final payloads...
Halcyon and Beazley Security published a joint report detailing the attack chain: compromised admin credentials, a week of dormancy, TeamViewer for access...
Today, the Pay2Key ransomware operation leaked data allegedly stolen from Habana Labs during a cyberattack.
The encryptor terminates 60+ services and 40+ processes before encryption, including: Services: AcronisAgent, BackupExecJobEngine, CAARCUpdateSvc... | The encryptor terminates 60+ services and 40+ processes before encryption, including... Processes: sqlservr, sqlagent, msaccess, mysqld, oracle, python, node, java, Raccine, Sysmon...
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tags: ... pay2key ... ransomware ... SamSam ...
Ransomware used by Fluffy Wolf for financial extortion; it uses anti-forensic behavior including overwriting its own executable with zeros via fsutil before deleting it.
Шифровальщик, развернутый в системе жертвы; шифрует файлы, добавляя расширение .ywgulm_p2k, и оставляет записку с требованием выкупа на русском, английском и испанском языках.
Iran-linked ransomware used against a U.S. healthcare organization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.