Skip to content

Pay2Key

Pay2Key is an Iran-linked ransomware operation active since 2020 and associated in multiple reports with state-aligned objectives rather than purely profit-driven cybercrime.

Profile source: Mallory opens in a new tab

Pay2Key

Family profile

Pay2Key is an Iran-linked ransomware operation active since 2020 and associated in multiple reports with state-aligned objectives rather than purely profit-driven cybercrime. It has been linked to Iranian threat activity and to clusters such as Fox Kitten/Pioneer Kitten, and has been described as operating through a ransomware-as-a-service model with affiliate recruitment, including outreach on Russian-language criminal forums. Victimology has included organizations in Israel, the United States, and other countries of strategic interest to Iran, with recent reporting highlighting attacks on healthcare and broader infrastructure-focused targeting.

Pay2Key is primarily a ransomware family used to encrypt victim systems for extortion, but its campaigns have also emphasized disruption, anti-forensics, and covert post-compromise operations. On Windows, operators have been observed using legitimate remote access software, credential theft utilities, network discovery tools, and Active Directory administration utilities before ransomware deployment. Reported tradecraft includes credential harvesting, lateral movement, disabling or bypassing endpoint protections, inhibiting recovery, clearing logs, and self-deletion or artifact destruction to hinder incident response and reverse engineering. Some incidents showed no confirmed data exfiltration, reinforcing assessments that certain Pay2Key operations may prioritize destructive or punitive impact over conventional double-extortion economics.

Technical reporting indicates that newer Pay2Key builds are based on the Mimic ransomware lineage, itself derived from leaked Conti code. Windows variants have been delivered in self-extracting archives and use strong modern cryptography for file encryption, including ChaCha20 for per-file encryption and asymmetric key protection mechanisms that make decryption impractical without operator-controlled private keys. The malware has also been observed using encrypted command-and-control communications and designating compromised machines as reverse-proxy pivots inside victim networks. Additional implementation details include service and process termination prior to encryption, filesystem enumeration, and intermittent encryption modes intended to accelerate impact across large environments.

A Linux variant, commonly referred to as Pay2Key.I2, extends the operation beyond desktop systems to organizational servers, virtualization hosts, and cloud workloads. This variant requires elevated privileges, disables Linux security controls such as SELinux and AppArmor, kills services and processes, enumerates mounted filesystems, and establishes reboot persistence through cron. Its behavior reflects deliberate targeting of infrastructure-layer assets and virtualized environments where rapid operational disruption can be maximized.

Observed delivery and intrusion chains include phishing campaigns by third-party operators that ultimately deploy Pay2Key, as well as post-compromise deployment after administrative access has already been obtained. In 2026 reporting, the malware appeared as a final payload in campaigns against Russian organizations, while separate incidents tied it to attacks on a U.S. healthcare provider. Across reporting, Pay2Key stands out as a ransomware platform at the intersection of state-aligned disruption, criminal affiliate ecosystems, and cross-platform enterprise targeting.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Spoofing

Reported operators

Threat actors

3 named in public reporting
Fluffy Wolf

When deploying the Pay2Key ransomware, the attackers employ heavy anti-forensic techniques to cover their tracks.

n3tw0rm

Early May 2021 saw another set of disruptive ransomware attacks attributed to Iran targeting Israel from the n3tw0rm ransomware group, a newly-identified threat actor with links to the 2020 Pay2Key attacks.

Fox Kitten

The disclosure comes as a U.S. healthcare organization was targeted in late February 2026 by Pay2Key, an Iranian ransomware gang with ties to the country's government. The ransomware-as-a-service (RaaS) operation, which has ties to the Fox Kitten group, first emerged in 2020.

MITRE ATT&CK

Pay2Key in ATT&CK

26 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.